ZeroHour

CVE-2020-35494

PoC
CVSS 3.1
6.1 medium
EPSS
1%p63
Published
()
Modified
Description

There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34.

Vendors
gnufedoraprojectnetappbroadcom
Products
binutils, fedora, cloud backup, ontap select deploy administration utility, solidfire\, enterprise sds \& hci storage node, solidfire \& hci management node, brocade fabric operating system firmware, hci compute node firmware
Weakness
CWE-908
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

In the news

No ingested article mentions this CVE yet.