Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-35342

Опубликовано: 27 дек. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.

GNU Binutils has an uninitialized-heap vulnerability in function tic4x_print_cond in opcodes/tic4x-dis.c file which could allow attackers to make an information leak.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6binutilsNot affected
Red Hat Enterprise Linux 7binutilsNot affected
Red Hat Enterprise Linux 7gdbNot affected
Red Hat Enterprise Linux 8binutilsNot affected
Red Hat Enterprise Linux 8gcc-toolset-11-binutilsNot affected
Red Hat Enterprise Linux 8gcc-toolset-11-gdbNot affected
Red Hat Enterprise Linux 8gcc-toolset-12-binutilsNot affected
Red Hat Enterprise Linux 8gcc-toolset-12-gdbNot affected
Red Hat Enterprise Linux 8gcc-toolset-13-binutilsNot affected
Red Hat Enterprise Linux 8gcc-toolset-13-gdbNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2233998binutils: uninitialized heap memory in tic4x_print_cond() in opcodes/tic4x-dis.c

EPSS

Процентиль: 30%
0.00109
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.

CVSS3: 7.5
nvd
больше 2 лет назад

GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.

CVSS3: 7.5
debian
больше 2 лет назад

GNU Binutils before 2.34 has an uninitialized-heap vulnerability in fu ...

CVSS3: 7.5
github
больше 2 лет назад

GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость функции tic4x_print_cond компонента opcodes/tic4x-dis.c программного средства разработки GNU Binutils, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 30%
0.00109
Низкий

7.5 High

CVSS3