CVE-2021-20294
HIGHbinutils 2.35-2.35.1 - Stack Buffer Overflow via Crafted File in readelf
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-20294. PoCs published by tin-z.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2021-20294, a vulnerability in GNU Binutils' readelf utility. The exploit leverages a crafted ELF file with an excessively long symbol version string to trigger a buffer overflow.
Description
A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to confidentiality, integrity, and availability.
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2021-20294, a vulnerability in GNU Binutils' readelf utility. The exploit leverages a crafted ELF file with an excessively long symbol version string to trigger a buffer overflow.
References (6)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H