First published: Tue Dec 29 2020(Updated: )
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/binutils | <2.34 | 2.34 |
GNU Binutils | <2.34 | |
Fedoraproject Fedora | =32 | |
Netapp Cloud Backup | ||
NetApp ONTAP Select Deploy administration utility | ||
IBM Cloud Pak for Business Automation | ||
Netapp Solidfire \& Hci Management Node | ||
Broadcom Brocade Fabric Operating System Firmware | ||
IBM Cloud Pak for Business Automation | ||
Netapp Hci Compute Node |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35493 is a vulnerability in binutils in bfd/pef.c that could cause a heap buffer overflow and out-of-bounds read.
CVE-2020-35493 could lead to an impact on application availability.
CVE-2020-35493 affects binutils versions prior to 2.34.
To fix CVE-2020-35493, update binutils to version 2.34 or later.
You can find more information about CVE-2020-35493 at the following references: - [Bugzilla Bug Report](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1911438) - [Sourceware Bug Report](https://sourceware.org/bugzilla/show_bug.cgi?id=25307) - [Binutils Git Commit](https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f2a3559d54602cecfec6d90f792be4a70ad918ab)