ZeroHour

CVE-2020-35493

PoC
CVSS 3.1
5.5 medium
EPSS
1%p63
Published
()
Modified
Description

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.

Vendors
gnufedoraprojectnetappbroadcom
Products
binutils, fedora, cloud backup, ontap select deploy administration utility, solidfire\, enterprise sds \& hci storage node, solidfire \& hci management node, brocade fabric operating system firmware, hci compute node firmware
Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.