First published: Sun Dec 27 2020(Updated: )
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | =2.35.1 | |
NetApp ONTAP Select Deploy administration utility |
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8642dafaef21aa6747cec01df1977e9c52eb4679
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35448 is a vulnerability in the Binary File Descriptor (BFD) library (aka libbfd) as distributed in GNU Binutils 2.35.1.
CVE-2020-35448 has a severity value of 3.3, which is considered medium.
CVE-2020-35448 affects GNU Binutils version 2.35.1 and NetApp ONTAP Select Deploy administration utility.
Yes, the fix for CVE-2020-35448 is included in Binutils version 2.36.
CVE-2020-35448 is associated with CWE-125, which is the Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability.