{"id":"CLSA-2022-1645466518","summary":"Fix of CVE: CVE-2021-20284, CVE-2021-20197, CVE-2021-42574, CVE-2021-3487, CVE-2020-35448","details":"- CVE-2021-42574: Developer environment: Unicode's bidirectional (BiDi) override characters can cause trojan source attacks (#2009172)\n- CVE-2021-20284: Heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c (#1961526)\n- CVE-2020-35448: Heap-based buffer overflow in bfd_getl_signed_32() in libbfd.c (#1953659)\n- CVE-2021-3487: Excessive debug section size can cause excessive memory consumption in bfd's dwarf2.c read_section() (#1947134)\n- CVE-2021-20197: Race window allows users to own arbitrary files (#1920642)","modified":"2026-06-01T00:33:19.096649425Z","published":"2022-02-21T18:01:58Z","upstream":["CVE-2021-20284","CVE-2021-20197","CVE-2021-42574","CVE-2021-3487","CVE-2020-35448"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/centos8.4-els/CLSA-2022-1645466518.html"}],"affected":[{"package":{"name":"binutils","ecosystem":"TuxCare:CentOS:8.4","purl":"pkg:rpm/tuxcare/binutils?distro=centos-8.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.30-93.el8.4.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.4els/CLSA-2022-1645466518.json"}},{"package":{"name":"binutils-devel","ecosystem":"TuxCare:CentOS:8.4","purl":"pkg:rpm/tuxcare/binutils-devel?distro=centos-8.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.30-93.el8.4.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.4els/CLSA-2022-1645466518.json"}}],"schema_version":"1.7.5"}