Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Improper Input Validation. A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.
Remediation
There is no fixed version for binutils
.
References
CVSS Score
5.5
low severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2020-35493
- CWE
- CWE-122 CWE-125 CWE-20
- Snyk ID
- SNYK-DEBIAN9-BINUTILS-1055022
- Disclosed
- 04 Jan, 2021
- Published
- 31 Dec, 2020