PT-2021-7940 · Gnu+2 · Binutils+2

Guilherme De Almeida Suckevicz

·

Published

2020-11-18

·

Updated

2022-09-02

·

CVE-2020-35494

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions binutils versions prior to 2.34
Description The issue is related to a flaw in the /opcodes/tic4x-dis.c component of binutils, which can cause the usage of uninitialized memory when a crafted input file is processed. This can lead to a threat to application availability and a lower threat to data confidentiality.
Recommendations For binutils versions prior to 2.34, update to version 2.34 or later to resolve the issue. As a temporary workaround, consider restricting the submission of crafted input files to minimize the risk of exploitation.

Exploit

Fix

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3352
ALT-PU-2020-3433
ALT-PU-2021-1230
BDU:2023-05794
CVE-2020-35494

Affected Products

Alt Linux
Astra Linux
Binutils