Vulnerability Details CVE-2021-20197
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.0%
CVSS Severity
CVSS v3 Score 6.3
CVSS v2 Score 3.3
Products affected by CVE-2021-20197
-
-
cpe:2.3:a:gnu:binutils:2.10
-
cpe:2.3:a:gnu:binutils:2.10.1
-
cpe:2.3:a:gnu:binutils:2.10.1a
-
cpe:2.3:a:gnu:binutils:2.11
-
cpe:2.3:a:gnu:binutils:2.11.1
-
cpe:2.3:a:gnu:binutils:2.11.2
-
cpe:2.3:a:gnu:binutils:2.11.2a
-
cpe:2.3:a:gnu:binutils:2.12
-
cpe:2.3:a:gnu:binutils:2.12.1
-
cpe:2.3:a:gnu:binutils:2.12.1a
-
cpe:2.3:a:gnu:binutils:2.13
-
cpe:2.3:a:gnu:binutils:2.13.1
-
cpe:2.3:a:gnu:binutils:2.13.2
-
cpe:2.3:a:gnu:binutils:2.13.2.1
-
cpe:2.3:a:gnu:binutils:2.13.2.1a
-
cpe:2.3:a:gnu:binutils:2.14
-
cpe:2.3:a:gnu:binutils:2.14a
-
cpe:2.3:a:gnu:binutils:2.15
-
cpe:2.3:a:gnu:binutils:2.15a
-
cpe:2.3:a:gnu:binutils:2.16.1
-
cpe:2.3:a:gnu:binutils:2.16.1a
-
cpe:2.3:a:gnu:binutils:2.17
-
cpe:2.3:a:gnu:binutils:2.17a
-
cpe:2.3:a:gnu:binutils:2.18
-
cpe:2.3:a:gnu:binutils:2.18a
-
cpe:2.3:a:gnu:binutils:2.19
-
cpe:2.3:a:gnu:binutils:2.19.1
-
cpe:2.3:a:gnu:binutils:2.19.1a
-
cpe:2.3:a:gnu:binutils:2.20
-
cpe:2.3:a:gnu:binutils:2.20.1
-
cpe:2.3:a:gnu:binutils:2.20.1a
-
cpe:2.3:a:gnu:binutils:2.21.1
-
cpe:2.3:a:gnu:binutils:2.21.1a
-
cpe:2.3:a:gnu:binutils:2.22
-
cpe:2.3:a:gnu:binutils:2.23
-
cpe:2.3:a:gnu:binutils:2.23.1
-
cpe:2.3:a:gnu:binutils:2.23.2
-
cpe:2.3:a:gnu:binutils:2.24
-
cpe:2.3:a:gnu:binutils:2.25
-
cpe:2.3:a:gnu:binutils:2.25.1
-
cpe:2.3:a:gnu:binutils:2.26
-
cpe:2.3:a:gnu:binutils:2.26.1
-
cpe:2.3:a:gnu:binutils:2.27
-
cpe:2.3:a:gnu:binutils:2.28
-
cpe:2.3:a:gnu:binutils:2.28.1
-
cpe:2.3:a:gnu:binutils:2.29
-
cpe:2.3:a:gnu:binutils:2.29.1
-
cpe:2.3:a:gnu:binutils:2.29.1.1
-
cpe:2.3:a:gnu:binutils:2.30
-
cpe:2.3:a:gnu:binutils:2.31
-
cpe:2.3:a:gnu:binutils:2.31.1
-
cpe:2.3:a:gnu:binutils:2.32
-
cpe:2.3:a:gnu:binutils:2.33
-
cpe:2.3:a:gnu:binutils:2.33.1
-
cpe:2.3:a:gnu:binutils:2.34
-
cpe:2.3:a:gnu:binutils:2.35
-
cpe:2.3:a:gnu:binutils:2.6
-
cpe:2.3:a:gnu:binutils:2.7
-
cpe:2.3:a:gnu:binutils:2.8
-
cpe:2.3:a:gnu:binutils:2.8.1
-
cpe:2.3:a:gnu:binutils:2.9
-
cpe:2.3:a:gnu:binutils:2.9.1
-
cpe:2.3:a:netapp:cloud_backup:-
-
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-
-
cpe:2.3:a:netapp:solidfire_&_hci_management_node:-
-
cpe:2.3:o:broadcom:brocade_fabric_operating_system_firmware:-
-
cpe:2.3:o:redhat:enterprise_linux:8.0