Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to NULL Pointer Dereference. There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.
Remediation
There is no fixed version for binutils
.
References
CVSS Score
5.5
low severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2020-35507
- CWE
- CWE-476
- Snyk ID
- SNYK-DEBIAN9-BINUTILS-1055155
- Disclosed
- 04 Jan, 2021
- Published
- 01 Jan, 2021