Vulnerabilities > CVE-2021-20197

047910
CVSS 6.3 - MEDIUM
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
local
high complexity
gnu
redhat
netapp
broadcom

Summary

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

Vulnerable Configurations

Part Description Count
Application
Gnu
63
Application
Netapp
3
OS
Redhat
1
OS
Broadcom
1