RHSA-2021:4364MediumCVSS 4.7
Red Hat Security Advisory: binutils security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2020-35448 — binutils: Heap-based buffer overflow in bfd_getl_signed_32() in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section() in elf.c CVE-2021-3487 — binutils: Excessive debug section size can cause excessive memory consumption in bfd's dwarf2.c read_section() CVE-2021-20197 — binutils: Race window allows users to own arbitrary files CVE-2021-20284 — binutils: Heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2021:4364
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.5_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1913743
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1924068
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1930988
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1935785
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1937784
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1946518
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1946977
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1947111
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1950478
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1969775
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_4364.json