CVE-2021-20284
published 2021-03-26CVE-2021-20284: A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of…
PriorityP421medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.29%
67.2th percentile
A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.37-3 (bookworm) | binutils 2.37-3 (bookworm) |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.37-3 | 2.37-3 |
| gnu | binutils | >= 0 < 2.37-3 | 2.37-3 |
| gnu | binutils | >= 0 < 2.37-3 | 2.37-3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-20284: binutils - A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer over...
vendor_debian·2021·CVSS 5.5
CVE-2021-20284 [MEDIUM] CVE-2021-20284: binutils - A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer over...
A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 2.37-3)
bullseye: open
forky: resolved (fixed in 2.37-3)
sid: resolved (fixed in 2.37-3)
trixie: resolved (fixed in 2.37-3)
Red Hat
binutils: Heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c
vendor_redhat·2020-11-22·CVSS 5.5
CVE-2021-20284 [MEDIUM] CWE-119 binutils: Heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c
binutils: Heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c
A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.
A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.
Package: binutils (Red Hat Enterprise Linux 6) - Not affected
Package: binutils (Red Hat Enterprise Linux 7) - Not affected
Package: gcc-toolset-10-binutils (Red Hat Enterprise Linux 8)
GHSA
GHSA-hm3m-qrrw-pfv7: A flaw was found in GNU Binutils 2
ghsa_unreviewed·2022-05-24
CVE-2021-20284 [MEDIUM] CWE-119 GHSA-hm3m-qrrw-pfv7: A flaw was found in GNU Binutils 2
A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.
OSV
CVE-2021-20284: A flaw was found in GNU Binutils 2
osv·2021-03-26·CVSS 5.5
CVE-2021-20284 [MEDIUM] CVE-2021-20284: A flaw was found in GNU Binutils 2
A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1937784https://security.gentoo.org/glsa/202208-30https://security.netapp.com/advisory/ntap-20210521-0010/https://sourceware.org/bugzilla/show_bug.cgi?id=26931https://bugzilla.redhat.com/show_bug.cgi?id=1937784https://security.gentoo.org/glsa/202208-30https://security.netapp.com/advisory/ntap-20210521-0010/https://sourceware.org/bugzilla/show_bug.cgi?id=26931
2021-03-26
Published