ZeroHour

CVE-2020-35496

PoC
CVSS 3.1
5.5 medium
EPSS
1%p65
Published
()
Modified
Description

There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw affects binutils versions prior to 2.34.

Vendors
gnufedoraprojectnetappbroadcom
Products
binutils, fedora, cloud backup, ontap select deploy administration utility, solidfire\, enterprise sds \& hci storage node, solidfire \& hci management node, brocade fabric operating system firmware, hci compute node firmware
Weakness
CWE-476
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.