A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.
2021-01-04T15:15:12.777
2024-11-21T05:27:24.997
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnu | binutils | < 2.34 | Yes |
Operating System | fedoraproject | fedora | 32 | Yes |
Application | netapp | cloud_backup | - | Yes |
Application | netapp | ontap_select_deploy_administration_utility | - | Yes |
Application | netapp | solidfire\,_enterprise_sds_\&_hci_storage_node | - | Yes |
Application | netapp | solidfire_\&_hci_management_node | - | Yes |
Operating System | broadcom | brocade_fabric_operating_system_firmware | - | Yes |
Operating System | netapp | hci_compute_node_firmware | - | Yes |
Hardware | netapp | hci_compute_node | - | No |