CVE-2021-20294
Summary
| CVE | CVE-2021-20294 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-29 16:15:00 UTC |
| Updated | 2023-11-07 03:29:00 UTC |
| Description | A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to confidentiality, integrity, and availability. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GNU Binutils: Multiple Vulnerabilities (GLSA 202208-30) — Gentoo security | GENTOO | security.gentoo.org | |
| sourceware.org Git | sourceware.org | ||
| [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| 26929 – [readelf] crash with ASAN in print_dynamic_symbol | MISC | sourceware.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 | lists.apache.org | ||
| 1943533 – (CVE-2021-20294) CVE-2021-20294 binutils: stack buffer overflow WRITE may lead to a DoS via a crafted ELF | MISC | bugzilla.redhat.com | |
| sourceware.org/git | MISC | sourceware.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180283 Debian Security Update for binutils (CVE-2021-20294)
- 296059 Oracle Solaris 11.4 Support Repository Update (SRU) 36.0.1.101.2 Missing (CPUJUL2021)
- 352841 Amazon Linux Security Advisory for gcc10-binutils: ALAS2-2021-1702
- 710599 Gentoo Linux GNU Binutils Multiple Vulnerabilities (GLSA 202208-30)
- 751339 SUSE Enterprise Linux Security Update for binutils (SUSE-SU-2021:3637-1)
- 751340 OpenSUSE Security Update for binutils (openSUSE-SU-2021:3643-1)
- 751350 OpenSUSE Security Update for binutils (openSUSE-SU-2021:1475-1)
- 751368 SUSE Enterprise Linux Security Update for binutils (SUSE-SU-2021:3643-1)
- 751916 SUSE Enterprise Linux Security Update for binutils (SUSE-SU-2022:0934-1)
- 900099 CBL-Mariner Linux Security Update for binutils 2.32
- 903191 Common Base Linux Mariner (CBL-Mariner) Security Update for binutils (4171)