First published: Tue Dec 29 2020(Updated: )
GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak. Reference: <a href="https://sourceware.org/bugzilla/show_bug.cgi?id=25319">https://sourceware.org/bugzilla/show_bug.cgi?id=25319</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/binutils | <2.34 | 2.34 |
GNU Binutils | <2.34 | |
Fedoraproject Fedora | =32 | |
Netapp Cloud Backup | ||
NetApp ONTAP Select Deploy administration utility | ||
IBM Cloud Pak for Business Automation | ||
Netapp Solidfire \& Hci Management Node | ||
Broadcom Brocade Fabric Operating System Firmware | ||
IBM Cloud Pak for Business Automation | ||
Netapp Hci Compute Node |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35494 is a vulnerability in binutils/opcodes/tic4x-dis.c that allows an attacker to cause usage of uninitialized memory.
The severity of CVE-2020-35494 is medium with a CVSS score of 6.1.
CVE-2020-35494 poses a high threat to application availability.
The impact of CVE-2020-35494 on data confidentiality is lower.
CVE-2020-35494 affects binutils version up to 2.34, GNU Binutils up to version 2.34, Fedoraproject Fedora version 32, Netapp Cloud Backup, NetApp ONTAP Select Deploy administration utility, Netapp Solidfire, Enterprise Sds & Hci Storage Node, Netapp Solidfire & Hci Management Node, Broadcom Brocade Fabric Operating System Firmware, and Netapp Hci Compute Node Firmware.