CVE-2020-16599
published 2020-12-09CVE-2020-16599: A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in…
PriorityP416medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.04%
60.2th percentile
A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.39.50.20221208-2 (bookworm) | binutils 2.39.50.20221208-2 (bookworm) |
| debian | binutils | < binutils 2.35-1 (bookworm) | binutils 2.35-1 (bookworm) |
| fedoraproject | fedora | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.35-1 | 2.35-1 |
| gnu | binutils | >= 0 < 2.35-1 | 2.35-1 |
| gnu | binutils | >= 0 < 2.39.50.20221208-2 | 2.39.50.20221208-2 |
| gnu | binutils | >= 0 < 2.35-1 | 2.35-1 |
| gnu | binutils | >= 0 < 2.39.50.20221208-2 | 2.39.50.20221208-2 |
| gnu | binutils | >= 0 < 2.35-1 | 2.35-1 |
| gnu | binutils | >= 0 < 2.39.50.20221208-2 | 2.39.50.20221208-2 |
| gnu | binutils | >= 2.35 < 2.39-7 | 2.39-7 |
| gnu | gdb | >= 0 < 9.2-0ubuntu1~20.04.2 | 9.2-0ubuntu1~20.04.2 |
| gnu | gdb | >= 0 < 12.1-0ubuntu1~22.04.2 | 12.1-0ubuntu1~22.04.2 |
| gnu | gdb | >= 0 < 7.11.1-0ubuntu1~16.5+esm1 | 7.11.1-0ubuntu1~16.5+esm1 |
| gnu | gdb | >= 0 < 8.1.1-0ubuntu1+esm1 | 8.1.1-0ubuntu1+esm1 |
| msrc | cbl2_binutils_2.37-5_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_binutils_2.36.1-3_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
gdb vulnerabilities
osv·2024-06-20·CVSS 5.5
CVE-2020-16599 [MEDIUM] gdb vulnerabilities
gdb vulnerabilities
It was discovered that gdb incorrectly handled certain memory operations
when parsing an ELF file. An attacker could possibly use this issue
to cause a denial of service. This issue is the result of an
incomplete fix for CVE-2020-16599. This issue only affected
Ubuntu 22.04 LTS. (CVE-2022-4285)
It was discovered that gdb incorrectly handled memory leading
to a heap based buffer overflow. An attacker could use this
issue to cause a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS.
(CVE-2023-1972)
It was discovered that gdb incorrectly handled memory leading
to a stack overflow. An attacker could possibly use this issue
to cause a denial of service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22
OSV
CVE-2022-4285: An illegal memory access flaw was found in the binutils package
osv·2023-01-27·CVSS 5.5
CVE-2022-4285 [MEDIUM] CVE-2022-4285: An illegal memory access flaw was found in the binutils package
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
GHSA
GHSA-qx33-qxjc-p36p: An illegal memory access flaw was found in the binutils package
ghsa_unreviewed·2023-01-27·CVSS 5.5
CVE-2022-4285 [MEDIUM] CWE-476 GHSA-qx33-qxjc-p36p: An illegal memory access flaw was found in the binutils package
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
GHSA
GHSA-77qx-69hx-pmqh: A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2
ghsa_unreviewed·2022-05-24
CVE-2020-16599 [MEDIUM] CWE-476 GHSA-77qx-69hx-pmqh: A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2
A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.34, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
OSV
CVE-2020-16599: A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2
osv·2020-12-09·CVSS 5.5
CVE-2020-16599 [MEDIUM] CVE-2020-16599: A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2
A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
Ubuntu
gdb vulnerabilities
vendor_ubuntu·2024-06-20·CVSS 5.5
CVE-2020-16599 [MEDIUM] gdb vulnerabilities
Title: gdb vulnerabilities
Summary: gdb could be made to crash if it opened a specially crafted file.
It was discovered that gdb incorrectly handled certain memory operations
when parsing an ELF file. An attacker could possibly use this issue
to cause a denial of service. This issue is the result of an
incomplete fix for CVE-2020-16599. This issue only affected
Ubuntu 22.04 LTS. (CVE-2022-4285)
It was discovered that gdb incorrectly handled memory leading
to a heap based buffer overflow. An attacker could use this
issue to cause a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS.
(CVE-2023-1972)
It was discovered that gdb incorrectly handled memory leading
to a stack overflow. An attacker could possibly use this issue
to cause a denial of
Microsoft
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an inc
vendor_msrc·2023-01-10·CVSS 5.5
CVE-2022-4285 [MEDIUM] CWE-476 An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an inc
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is
Red Hat
binutils: NULL pointer dereference in _bfd_elf_get_symbol_version_string leads to segfault
vendor_redhat·2022-10-19·CVSS 5.5
CVE-2022-4285 [MEDIUM] CWE-476 binutils: NULL pointer dereference in _bfd_elf_get_symbol_version_string leads to segfault
binutils: NULL pointer dereference in _bfd_elf_get_symbol_version_string leads to segfault
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
Package: binutils (Red Hat Enterprise Linux 6) - Out of support scope
Package: binutils (Red Hat Enterprise Linux 7) - Will not fix
Package: gdb (Red Hat Enterprise Linux 7) - Will not fix
Package: gcc-toolset-11-binutils (Red Hat Enterpri
Debian
CVE-2022-4285: binutils - An illegal memory access flaw was found in the binutils package. Parsing an ELF ...
vendor_debian·2022·CVSS 5.5
CVE-2022-4285 [MEDIUM] CVE-2022-4285: binutils - An illegal memory access flaw was found in the binutils package. Parsing an ELF ...
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
Scope: local
bookworm: resolved (fixed in 2.39.50.20221208-2)
bullseye: open
forky: resolved (fixed in 2.39.50.20221208-2)
sid: resolved (fixed in 2.39.50.20221208-2)
trixie: resolved (fixed in 2.39.50.20221208-2)
Red Hat
binutils: Null Pointer Dereference in _bfd_elf_get_symbol_version_string could result in DoS
vendor_redhat·2020-12-10·CVSS 5.5
CVE-2020-16599 [MEDIUM] CWE-476 binutils: Null Pointer Dereference in _bfd_elf_get_symbol_version_string could result in DoS
binutils: Null Pointer Dereference in _bfd_elf_get_symbol_version_string could result in DoS
A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
Statement: binutils as shipped in Red Hat Developer Toolsets 9 and 10, Red Hat Enterprise Linux 8 BaseOS and GCC Toolsets 9 and 10, are all not affected by this flaw as it was introduced in a newer version of binutils code than shipped for BaseOS and the 9 toolsets, and already patched in the versions shipped with 10 toolsets.
Package: binutils (Red Hat Enterprise Linux 5) - Out of support scope
Package: binutils220 (Red Hat Enterprise
Debian
CVE-2020-16599: binutils - A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (B...
vendor_debian·2020·CVSS 5.5
CVE-2020-16599 [MEDIUM] CVE-2020-16599: binutils - A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (B...
A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.35-1)
bullseye: resolved (fixed in 2.35-1)
forky: resolved (fixed in 2.35-1)
sid: resolved (fixed in 2.35-1)
trixie: resolved (fixed in 2.35-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://security.netapp.com/advisory/ntap-20210122-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=25842https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=8d55d10ac0d112c586eaceb92e75bd9b80aadcc4https://security.netapp.com/advisory/ntap-20210122-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=25842https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=8d55d10ac0d112c586eaceb92e75bd9b80aadcc4
2020-12-09
Published