VDB

CVE-2020-35494

CVE-2020-35494 REJECTED CVSS 6.099999904632568 MEDIUM

There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34.

EPSS 1.09% · 64.1th percentile

Risk Scores

CVSS 3.1
6.099999904632568
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
EPSS Score
1.09%
64.1th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSbinutils0, 2.33-2ubuntu1, 2.33.1-1ubuntu1

Timeline

  • Jan 4, 2021 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Dec 29, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 3, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 5, 2022 EPSS Score
  • Sep 9, 2022 EPSS Score
  • Nov 11, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›