PT-2021-7938 · Gnu+1 · Gnu Binutils+1

Guilherme De Almeida Suckevicz

·

Published

2021-05-26

·

Updated

2025-02-28

·

CVE-2021-3549

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU binutils version 2.36
Description An out of bounds flaw was found in the GNU binutils objdump utility. This issue is related to the avr elf32 load records from section() function and can result in a crash or memory corruption if a large section is passed to it. The highest threat from this issue is to system integrity and availability.
Recommendations For GNU binutils version 2.36, consider disabling the avr elf32 load records from section() function as a temporary workaround until a patch is available. Restrict access to the objdump utility to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-05788
CVE-2021-3549
OESA-2021-1242

Affected Products

Debian
Gnu Binutils