There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.
2021-01-04T15:15:15.200
2024-11-21T05:27:27.300
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnu | binutils | < 2.34 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |
Operating System | netapp | hci_compute_node_firmware | - | Yes |
Hardware | netapp | hci_compute_node | - | No |
Application | netapp | cloud_backup | - | Yes |
Application | netapp | ontap_select_deploy_administration_utility | - | Yes |
Application | netapp | solidfire\,_enterprise_sds_\&_hci_storage_node | - | Yes |
Application | netapp | solidfire_\&_hci_management_node | - | Yes |
Operating System | broadcom | brocade_fabric_operating_system | - | Yes |