VYPR

rpm package

opensuse/bpftrace&distro=openSUSE Leap 15.3

pkg:rpm/opensuse/bpftrace&distro=openSUSE%20Leap%2015.3

Vulnerabilities (11)

  • CVE-2021-20197Mar 26, 2021
    affected < 0.11.4-3.2.1fixed 0.11.4-3.2.1

    There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivi

  • CVE-2021-20284Mar 26, 2021
    affected < 0.11.4-3.2.1fixed 0.11.4-3.2.1

    A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.

  • CVE-2020-35507Jan 4, 2021
    affected < 0.11.4-3.2.1fixed 0.11.4-3.2.1

    There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application

  • CVE-2020-35496Jan 4, 2021
    affected < 0.11.4-3.2.1fixed 0.11.4-3.2.1

    There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw af

  • CVE-2020-35493Jan 4, 2021
    affected < 0.11.4-3.2.1fixed 0.11.4-3.2.1

    A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.3

  • CVE-2020-35448Dec 27, 2020
    affected < 0.11.4-3.2.1fixed 0.11.4-3.2.1

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.

  • CVE-2020-16599Dec 9, 2020
    affected < 0.11.4-3.2.1fixed 0.11.4-3.2.1

    A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file.

  • CVE-2020-16593Dec 9, 2020
    affected < 0.11.4-3.2.1fixed 0.11.4-3.2.1

    A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in scan_unit_for_symbols, as demonstrated in addr2line, that can cause a denial of service via a crafted file.

  • CVE-2020-16592Dec 9, 2020
    affected < 0.11.4-3.2.1fixed 0.11.4-3.2.1

    A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.

  • CVE-2020-16591Dec 9, 2020
    affected < 0.11.4-3.2.1fixed 0.11.4-3.2.1

    A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read in process_symbol_table, as demonstrated in readeif.

  • CVE-2020-16590Dec 9, 2020
    affected < 0.11.4-3.2.1fixed 0.11.4-3.2.1

    A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as demonstrated in readelf, via a crafted file.