CVE-2021-20294
- EPSS 15.05%
- Veröffentlicht 29.04.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 05:46:17
A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest im...
CVE-2021-20284
- EPSS 0.09%
- Veröffentlicht 26.03.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:16
A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system ava...
CVE-2021-20197
- EPSS 0.12%
- Veröffentlicht 26.03.2021 17:15:12
- Zuletzt bearbeitet 03.12.2025 15:15:46
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries acros...
CVE-2020-35507
- EPSS 0.21%
- Veröffentlicht 04.01.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:27:27
There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat o...
CVE-2020-35496
- EPSS 0.21%
- Veröffentlicht 04.01.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:27:25
There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to applicat...
CVE-2020-35494
- EPSS 0.11%
- Veröffentlicht 04.01.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:27:25
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to da...
CVE-2020-35495
- EPSS 0.12%
- Veröffentlicht 04.01.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:27:25
There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw ...
CVE-2020-35493
- EPSS 0.23%
- Veröffentlicht 04.01.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:27:24
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects ...
CVE-2020-35448
- EPSS 0.13%
- Veröffentlicht 27.12.2020 04:15:12
- Zuletzt bearbeitet 21.11.2024 05:27:17
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_s...
CVE-2020-16590
- EPSS 0.33%
- Veröffentlicht 09.12.2020 21:15:15
- Zuletzt bearbeitet 21.11.2024 05:07:10
A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as demonstrated in readelf, via a crafted file.