CVE-2020-35448: Medium severity GNU binutils vulnerability
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfdgetlsigned32 in libbfd.c because shentsize is not validated in bfdelfslurpsecondaryrelocsection in elf.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-35448?
CVE-2020-35448 is a vulnerability in the Binary File Descriptor (BFD) library (aka libbfd) as distributed in GNU Binutils 2.35.1.
What is the severity of CVE-2020-35448?
CVE-2020-35448 has a severity value of 3.3, which is considered medium.
How does CVE-2020-35448 affect the software?
CVE-2020-35448 affects GNU Binutils version 2.35.1 and NetApp ONTAP Select Deploy administration utility.
Is there a fix available for CVE-2020-35448?
Yes, the fix for CVE-2020-35448 is included in Binutils version 2.36.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-35448?
CVE-2020-35448 is associated with CWE-125, which is the Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability.