CLSA-2022-1645466518
Dashboard / Vulnerabilities / CLSA-2022-1645466518
CLSA-2022-1645466518
Summary: Fix of CVE: CVE-2021-20284, CVE-2021-20197, CVE-2021-42574, CVE-2021-3487, CVE-2020-35448
Details: - CVE-2021-42574: Developer environment: Unicode's bidirectional (BiDi) override characters can cause trojan source attacks (#2009172) - CVE-2021-20284: Heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c (#1961526) - CVE-2020-35448: Heap-based buffer overflow in bfd_getl_signed_32() in libbfd.c (#1953659) - CVE-2021-3487: Excessive debug section size can cause excessive memory consumption in bfd's dwarf2.c read_section() (#1947134) - CVE-2021-20197: Race window allows users to own arbitrary files (#1920642)
Affected packages
Package
Name: binutils
Purl: pkg:rpm/tuxcare/binutils?distro=centos-8.4
Affected ranges
Type: ECOSYSTEM
Events:
