{"id":"CVE-2020-35493","title":"A flaw exists in binutils in bfd/pef.c","summary":"A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This …","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-20"],"vendor":"gnu","product":"binutils","affected":["binutils < 2.34","fedora = 32","cloud_backup","ontap_select_deploy_administration_utility","solidfire,_enterprise_sds_&_hci_storage_node","solidfire_&_hci_management_node","brocade_fabric_operating_system_firmware","hci_compute_node_firmware"],"patched":["binutils 2.34"],"published":"2021-01-04","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:59.583","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-35493","references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1911437","label":"secalert@redhat.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/","label":"secalert@redhat.com"},{"url":"https://security.gentoo.org/glsa/202107-24","label":"secalert@redhat.com"},{"url":"https://security.netapp.com/advisory/ntap-20210212-0007/","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1911437","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202107-24","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210212-0007/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01098,"epssPercentile":0.64619,"ingestedAt":"2026-10-08T23:16:47.311Z","slug":"CVE-2020-35493","body":"## Overview\n\nA flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.\n\n## Affected\n\n- `binutils < 2.34`\n- `fedora = 32`\n- `cloud_backup`\n- `ontap_select_deploy_administration_utility`\n- `solidfire,_enterprise_sds_&_hci_storage_node`\n- `solidfire_&_hci_management_node`\n- `brocade_fabric_operating_system_firmware`\n- `hci_compute_node_firmware`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `binutils 2.34`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}