First published: Tue Dec 29 2020(Updated: )
GNU Binutils before 2.34 has a NULL pointer deference vulnerability in function bfd_pef_parse_symbols (file bfd/pef.c) which could allow attackers to cause a denial of service. Reference: <a href="https://sourceware.org/bugzilla/show_bug.cgi?id=25306">https://sourceware.org/bugzilla/show_bug.cgi?id=25306</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/binutils | <2.34 | 2.34 |
GNU Binutils | <2.34 | |
Fedoraproject Fedora | =32 | |
Netapp Cloud Backup | ||
NetApp ONTAP Select Deploy administration utility | ||
IBM Cloud Pak for Business Automation | ||
Netapp Solidfire \& Hci Management Node | ||
Broadcom Brocade Fabric Operating System Firmware | ||
IBM Cloud Pak for Business Automation | ||
Netapp Hci Compute Node |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35495 is a vulnerability in binutils /bfd/pef.c that allows an attacker to cause a null pointer dereference by submitting a crafted input file to the objdump program.
The greatest threat from CVE-2020-35495 is to application availability.
CVE-2020-35495 affects binutils versions prior to 2.34.
To fix CVE-2020-35495, you should upgrade to binutils version 2.34 or higher.
You can find more information about CVE-2020-35495 at the following references: [1](https://sourceware.org/bugzilla/show_bug.cgi?id=25306), [2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1911442), [3](https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7a0fb7be96e0ce79e1ae429bc1ba913e5244d537).