PT-2019-6405 · Gnu+2 · Binutils+2
Published
2019-12-21
·
Updated
2022-09-02
·
CVE-2020-35495
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
binutils versions prior to 2.34
Description
The issue is related to a flaw in the /bfd/pef.c component of the GNU Binutils software development tool, which is associated with null pointer dereference errors. An attacker can exploit this flaw by submitting a specially crafted input file to be processed by the objdump program, potentially causing a denial of service. The greatest threat from this flaw is to application availability.
Recommendations
For binutils versions prior to 2.34, update to version 2.34 or later to resolve the issue. As a temporary workaround, consider restricting the use of the objdump program to minimize the risk of exploitation. Avoid processing untrusted or specially crafted input files with the objdump program until the issue is resolved.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Binutils