CVE-2021-3549
Last modified
CVE-2021-3549 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Binutils | 2.36 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1960717Issue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202208-30Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1960717Issue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202208-30Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3549?
How severe is CVE-2021-3549?
How do I fix CVE-2021-3549?
Are you affected by CVE-2021-3549?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
