VDB
CVE-2020-35342
CVE-2020-35342
PUBLISHED
CVSS 7.5 HIGH
GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.
EPSS 0.77% · 53.8th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.77%
53.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:18.04:LTS | binutils | 2.29.1-8ubuntu1, 2.30-7ubuntu1, 2.30-11ubuntu1 |
| Ubuntu:Pro:16.04:LTS | binutils | 2.26.1-1ubuntu1~16.04.8+esm3, 2.26.1-1ubuntu1~16.04.8+esm4, 2.26.1-1ubuntu1~16.04.8+esm5 |
| Ubuntu:Pro:14.04:LTS | binutils | 2.24-5ubuntu14, *, 2.24-5ubuntu14.2+esm2 |
Timeline
- Aug 22, 2023 CVE Published
- Aug 22, 2023 PoC Published
- Aug 23, 2023 EPSS Score
- Sep 26, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Dec 2, 2023 EPSS Score
- Jan 5, 2024 EPSS Score
- Feb 8, 2024 EPSS Score
- Mar 13, 2024 EPSS Score
- Mar 14, 2024 CVE Updated
- Apr 15, 2024 EPSS Score
- May 19, 2024 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-35342 third-party-advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=25319 third-party-advisory
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8c5e259235a4e4546910245b170de1e29a711034 third-party-advisory
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=2c5b6e1a1c406cbe06e2d6f77861764ebd01b9ce third-party-advisory
- https://ubuntu.com/security/notices/USN-6381-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-35342 third-party-advisory