Логотип exploitDog
bind:"CVE-2021-3487" OR bind:"CVE-2021-20284" OR bind:"CVE-2021-20197" OR bind:"CVE-2020-35448"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-3487" OR bind:"CVE-2021-20284" OR bind:"CVE-2021-20197" OR bind:"CVE-2020-35448"

Количество 31

Количество 31

nvd логотип

CVE-2020-35448

почти 5 лет назад

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c.

CVSS3: 3.3
EPSS: Низкий
debian логотип

CVE-2020-35448

почти 5 лет назад

An issue was discovered in the Binary File Descriptor (BFD) library (a ...

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2021-20197

больше 4 лет назад

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2021-20197

почти 5 лет назад

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2021-20197

больше 4 лет назад

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

CVSS3: 6.3
EPSS: Низкий
msrc логотип

CVE-2021-20197

больше 4 лет назад

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2021-20197

больше 4 лет назад

There is an open race window when writing output in the following util ...

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-r2cj-jqqc-j833

больше 3 лет назад

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c.

CVSS3: 3.3
EPSS: Низкий
fstec логотип

BDU:2023-05790

почти 5 лет назад

Уязвимость библиотеки libbfd программного средства разработки GNU Binutils, связанная с чтением за границами буфера в памяти, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-rq67-5wpf-96wv

больше 3 лет назад

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

CVSS3: 6.3
EPSS: Низкий
fstec логотип

BDU:2023-05789

больше 4 лет назад

Уязвимость программного средства разработки GNU Binutils, связанная с некорректным определением ссылки перед доступом к файлу, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-35448

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c.

CVSS3: 3.3
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-35448

An issue was discovered in the Binary File Descriptor (BFD) library (a ...

CVSS3: 3.3
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-20197

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

CVSS3: 6.3
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-20197

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

CVSS3: 4.2
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-20197

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

CVSS3: 6.3
0%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 6.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-20197

There is an open race window when writing output in the following util ...

CVSS3: 6.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-r2cj-jqqc-j833

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2023-05790

Уязвимость библиотеки libbfd программного средства разработки GNU Binutils, связанная с чтением за границами буфера в памяти, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.3
0%
Низкий
почти 5 лет назад
github логотип
GHSA-rq67-5wpf-96wv

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2023-05789

Уязвимость программного средства разработки GNU Binutils, связанная с некорректным определением ссылки перед доступом к файлу, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.3
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу