Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 33: FEDORA-2020-18ec0bf4bb Critical: Mingw-binutils DoS Patches

fedora
Calendar Grey December 26, 2020
Dist Fedora Esm H88
Critical updates released for mingw-binutils in Fedora 33 to tackle significant vulnerabilities. Installation instructions and severity levels provided.
Backport patches for CVE-2020-16592 and CVE-2020-16598

Summary

Cross compiled binutils (utilities like 'strip', 'as', 'ld') which

understand Windows executables and DLLs.

Backport patches for CVE-2020-16592 and CVE-2020-16598

* Fri Dec 18 2020 Sandro Mani - 2.34-4

- Backport patches for CVE-2020-16592, CVE-2020-16598

* Wed Jul 29 2020 Sandro Mani - 2.34-3

- Fix ld --version output

[ 1 ] Bug #1906758 - CVE-2020-16598 mingw-binutils: binutils: Null Pointer Dereference in debug_get_real_type could result in DoS [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1906758

[ 2 ] Bug #1906779 - CVE-2020-16592 mingw-binutils: binutils: use-after-free in bfd_hash_lookup could result in DoS [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1906779

su -c 'dnf upgrade --advisory FEDORA-2020-18ec0bf4bb' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 33
Version: 2.34
Release: 4.fc33
Summary: Cross-compiled version of binutils for Win32 and Win64 environments

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here