First published: Thu Jan 07 2021(Updated: )
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | <=2.35 | |
Redhat Enterprise Linux | =8.0 | |
Netapp Cloud Backup | ||
NetApp ONTAP Select Deploy administration utility | ||
IBM Cloud Pak for Business Automation | ||
Broadcom Brocade Fabric Operating System Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20197 is a vulnerability in GNU binutils version 2.35 and earlier, which allows an unprivileged user to trick a privileged user into overwriting arbitrary files.
CVE-2021-20197 has a severity rating of 6.3 (medium).
The following utilities in GNU binutils version 2.35 and earlier are affected: ar, objcopy, strip, ranlib.
The affected operating systems include Redhat Enterprise Linux 8.0, Netapp Cloud Backup, NetApp ONTAP Select Deploy administration utility, Netapp Solidfire & Hci Management Node, and Broadcom Brocade Fabric Operating System Firmware.
Yes, you can find more information about CVE-2021-20197 at the following references: [Link 1], [Link 2], [Link 3].