Improper Initialization in Binutils - CVE-2020-35342
Published: April 16, 2024
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to GNU Binutils has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c). A remote attacker can run a specially crafted application to execute arbitrary code with escalated privileges on the system.
Affected software
Ubuntu
binutils (Ubuntu package)
binutils-multiarch (Ubuntu package)
IBM Sterling Order Management
How to mitigate CVE-2020-35342
binutils (Ubuntu package) - update to Ubuntu Pro (Infra-only)
binutils-multiarch (Ubuntu package) - update to Ubuntu Pro (Infra-only)
IBM Sterling Order Management - update to 10.0.2403.1