CVE-2020-16592
published 2020-12-09CVE-2020-16592: A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.05%
60.6th percentile
A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.35-1 (bookworm) | binutils 2.35-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.35-1 | 2.35-1 |
| gnu | binutils | >= 0 < 2.35-1 | 2.35-1 |
| gnu | binutils | >= 0 < 2.35-1 | 2.35-1 |
| gnu | binutils | >= 0 < 2.35-1 | 2.35-1 |
| gnu | binutils | >= 0 < 2.30-21ubuntu1~18.04.7 | 2.30-21ubuntu1~18.04.7 |
| gnu | binutils | >= 0 < 2.34-6ubuntu1.3 | 2.34-6ubuntu1.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2q8c-vq6v-7pf3: A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2
ghsa_unreviewed·2022-05-24
CVE-2020-16592 [MEDIUM] CWE-416 GHSA-2q8c-vq6v-7pf3: A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2
A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
OSV
binutils vulnerabilities
osv·2021-10-25·CVSS 5.5
CVE-2020-16592 [MEDIUM] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled certain hash
lookups. An attacker could use this issue to cause GNU binutils to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2020-16592)
It was discovered that GNU binutils incorrectly handled certain corrupt
DWARF debug sections. An attacker could possibly use this issue to cause
GNU binutils to consume memory, resulting in a denial of service.
(CVE-2021-3487)
OSV
CVE-2020-16592: A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2
osv·2020-12-09·CVSS 5.5
CVE-2020-16592 [MEDIUM] CVE-2020-16592: A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2
A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2021-10-25·CVSS 5.5
CVE-2021-3487 [MEDIUM] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils incorrectly handled certain hash
lookups. An attacker could use this issue to cause GNU binutils to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2020-16592)
It was discovered that GNU binutils incorrectly handled certain corrupt
DWARF debug sections. An attacker could possibly use this issue to cause
GNU binutils to consume memory, resulting in a denial of service.
(CVE-2021-3487)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
binutils: use-after-free in bfd_hash_lookup could result in DoS
vendor_redhat·2020-12-10·CVSS 5.5
CVE-2020-16592 [MEDIUM] CWE-416 binutils: use-after-free in bfd_hash_lookup could result in DoS
binutils: use-after-free in bfd_hash_lookup could result in DoS
A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
Statement: binutils as shipped in Red Hat Developer Toolsets 9 and 10, Red Hat Enterprise Linux 8 BaseOS and GCC Toolsets 9 and 10, are all not affected by this flaw as it was introduced in a newer version of binutils code than shipped for BaseOS and the 9 toolsets, and already patched in the versions shipped with 10 toolsets.
Package: binutils (Red Hat Enterprise Linux 5) - Out of support scope
Package: binutils220 (Red Hat Enterprise Linux 5) - Out of support scope
Package: binutils (Red Hat Enterprise Linux 6) -
Debian
CVE-2020-16592: binutils - A use after free issue exists in the Binary File Descriptor (BFD) library (aka l...
vendor_debian·2020·CVSS 5.5
CVE-2020-16592 [MEDIUM] CVE-2020-16592: binutils - A use after free issue exists in the Binary File Descriptor (BFD) library (aka l...
A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.35-1)
bullseye: resolved (fixed in 2.35-1)
forky: resolved (fixed in 2.35-1)
sid: resolved (fixed in 2.35-1)
trixie: resolved (fixed in 2.35-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJIW6KKY2TSLD43XEZXG56WREIIBUIIQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKIMSD5FIC3QFJDKNHR2PSO6JYJGCLHB/https://security.netapp.com/advisory/ntap-20210115-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=25823https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=7ecb51549ab1ec22aba5aaf34b70323cf0b8509ahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DJIW6KKY2TSLD43XEZXG56WREIIBUIIQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKIMSD5FIC3QFJDKNHR2PSO6JYJGCLHB/https://security.netapp.com/advisory/ntap-20210115-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=25823https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=7ecb51549ab1ec22aba5aaf34b70323cf0b8509a
2020-12-09
Published