gnu binutils CVE-2020-35494 vulnerability in GNU and Other Products
Published on January 4, 2021

product logo product logo product logo product logo
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34.

Vendor Advisory Vendor Advisory NVD

Weakness Type

Use of Uninitialized Resource

The software uses or accesses a resource that has not been initialized. When a resource has not been properly initialized, the software may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the software.


Products Associated with CVE-2020-35494

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-35494 are published in these products:

 
 
 
 
 
 
 
 
 
 

Exploit Probability

EPSS
0.11%
Percentile
29.92%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.