CVE-2020-35448
Summary
| CVE | CVE-2020-35448 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-27 04:15:00 UTC |
| Updated | 2023-11-07 03:21:00 UTC |
| Description | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| sourceware.org Git - binutils-gdb.git/commit |
|
sourceware.org |
|
| Binutils: Multiple vulnerabilities (GLSA 202107-24) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| 26574 – A heap buffer overflow in bfd_getl_signed_32 |
MISC |
sourceware.org |
Exploit, Issue Tracking, Third Party Advisory |
| sourceware.org Git - binutils-gdb.git/commit |
MISC |
sourceware.org |
Patch, Third Party Advisory |
| CVE-2020-35448 GNU Binutils Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159495 Oracle Enterprise Linux Security Update for binutils (ELSA-2021-4364)
- 239817 Red Hat Update for binutils (RHSA-2021:4364)
- 352841 Amazon Linux Security Advisory for gcc10-binutils: ALAS2-2021-1702
- 501880 Alpine Linux Security Update for mingw-w64-binutils
- 502041 Alpine Linux Security Update for binutils-cross-embedded
- 504587 Alpine Linux Security Update for binutils-cross-embedded
- 710052 Gentoo Linux Binutils Multiple vulnerabilities (GLSA 202107-24)
- 751313 SUSE Enterprise Linux Security Update for binutils (SUSE-SU-2021:3593-1)
- 751321 SUSE Enterprise Linux Security Update for binutils (SUSE-SU-2021:3616-1)
- 751331 OpenSUSE Security Update for binutils (openSUSE-SU-2021:3616-1)
- 751350 OpenSUSE Security Update for binutils (openSUSE-SU-2021:1475-1)
- 751916 SUSE Enterprise Linux Security Update for binutils (SUSE-SU-2022:0934-1)
- 940080 AlmaLinux Security Update for binutils (ALSA-2021:4364)
- 960767 Rocky Linux Security Update for binutils (RLSA-2021:4364)