Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE: 2018:3224-1 Moderate: gcc Denial Of Service Vulnerabilities

opensuse
Calendar Grey October 18, 2018
Dist Opensuse Esm H88
A recent enhancement for openSUSE binutils resolves 52 security vulnerabilities through patches. Find more information here.
An update that solves 52 vulnerabilities and has two fixes is now available.

Description

This update for binutils to 2.31 fixes the following issues:

These security issues were fixed:

- CVE-2017-15996: readelf allowed remote attackers to cause a denial of

service (excessive memory allocation) or possibly have unspecified other

impact via a crafted ELF file that triggered a buffer overflow on fuzzed

archive header (bsc#1065643).

- CVE-2017-15939: Binary File Descriptor (BFD) library (aka libbfd)

mishandled NULL files in a .debug_line file table, which allowed remote

attackers to cause a denial of service (NULL pointer dereference and

application crash) via a crafted ELF file, related to concat_filename

(bsc#1065689).

- CVE-2017-15938: the Binary File Descriptor (BFD) library (aka libbfd)

miscalculated DW_FORM_ref_addr die refs in the case of a relocatable

object file, which allowed remote attackers to cause a denial of service

(find_abstract_instance_name invalid memory read, segmentation fault,

and...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-1198=1

Package List

- openSUSE Leap 42.3 (i586 x86_64):

binutils-2.31-19.1

binutils-debuginfo-2.31-19.1

binutils-debugsource-2.31-19.1

binutils-devel-2.31-19.1

binutils-gold-2.31-19.1

binutils-gold-debuginfo-2.31-19.1

cross-aarch64-binutils-2.31-19.1

cross-aarch64-binutils-debuginfo-2.31-19.1

cross-aarch64-binutils-debugsource-2.31-19.1

cross-arm-binutils-2.31-19.1

cross-arm-binutils-debuginfo-2.31-19.1

cross-arm-binutils-debugsource-2.31-19.1

cross-avr-binutils-2.31-19.1

cross-avr-binutils-debuginfo-2.31-19.1

cross-avr-binutils-debugsource-2.31-19.1

cross-hppa-binutils-2.31-19.1

cross-hppa-binutils-debuginfo-2.31-19.1

cross-hppa-binutils-debugsource-2.31-19.1

cross-hppa64-binutils-2.31-19.1

cross-hppa64-binutils-debuginfo-2.31-19.1

cross-hppa64-binutils-debugsource-2.31-19.1

cross-ia64-binutils-2.31-19.1

cross-ia64-binutils-debuginfo-2.31-19.1

cross-ia64-binutils-debugsource-2.31-19.1

cross-m68k-binutils-2.31-19.1

cross-m68k-binutils-debuginfo-2.31-19.1

cross-m68k-binutils-debugsource-2.31-19.1

cross-mips-binutils-2.31-19.1

cross-mi...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2014-9939.html

https://www.suse.com/security/cve/CVE-2017-15938.html

https://www.suse.com/security/cve/CVE-2017-15939.html

https://www.suse.com/security/cve/CVE-2017-15996.html

https://www.suse.com/security/cve/CVE-2017-16826.html

https://www.suse.com/security/cve/CVE-2017-16827.html

https://www.suse.com/security/cve/CVE-2017-16828.html

https://www.suse.com/security/cve/CVE-2017-16829.html

https://www.suse.com/security/cve/CVE-2017-16830.html

https://www.suse.com/security/cve/CVE-2017-16831.html

https://www.suse.com/security/cve/CVE-2017-16832.html

https://www.suse.com/security/cve/CVE-2017-6965.html

https://www.suse.com/security/cve/CVE-2017-6966.html

https://www.suse.com/security/cve/CVE-2017-6969.html

https://www.suse.com/security/cve/CVE-2017-7209.html

https://www.suse.com/security/cve/CVE-2017-7210.html

https://www.suse.com/security/cve/CVE-2017-7223.html

https://www.suse.com/security/cve/CVE-2017-7224.html

https://www.suse.com/security/cve/CVE-2017-7225.html

ht...

Read the Full Advisory

Announcement ID: openSUSE-SU-2018:3223-1
Rating: moderate
Affected Products: openSUSE Leap 42.3 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here