CVE-2020-35494Medium· 6.1▾ SunlitThere's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.1%
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34.
binutils < 2.34fedora = 32cloud_backupontap_select_deploy_administration_utilitysolidfire,_enterprise_sds_&_hci_storage_nodesolidfire_&_hci_management_nodebrocade_fabric_operating_system_firmwarehci_compute_node_firmwareUpgrade past the affected range:
binutils 2.34Connected by shared product, vendor, weakness, or advisory.
CVE-2020-35507Medium· 5.5There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference
CVE-2020-35495Medium· 5.5There's a flaw in binutils /bfd/pef.c
CVE-2020-35496Medium· 5.5There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference
CVE-2020-35493Medium· 5.5A flaw exists in binutils in bfd/pef.c
CVE-2019-12972Medium· 5.5An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32
CVE-2019-14250Medium· 5.5An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32