This update for binutils to version 2.31 fixes the following issues:
These security issues were fixed:
- CVE-2017-15996: readelf allowed remote attackers to cause a denial of
service (excessive memory allocation) or possibly have unspecified other
impact via a crafted ELF file that triggered a buffer overflow on fuzzed
archive header (bsc#1065643)
- CVE-2017-15939: Binary File Descriptor (BFD) library (aka libbfd)
mishandled NULL files in a .debug_line file table, which allowed remote
attackers to cause a denial of service (NULL pointer dereference and
application crash) via a crafted ELF file, related to concat_filename
(bsc#1065689)
- CVE-2017-15938: the Binary File Descriptor (BFD) library (aka libbfd)
miscalculated DW_FORM_ref_addr die refs in the case of a relocatable
object file, which allowed remote attackers to cause a denial of service
(find_abstract_instance_name invalid memory read, segmentation fault,
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-1222=1
- openSUSE Leap 15.0 (i586 x86_64):
binutils-2.31-lp150.5.3.1
binutils-debuginfo-2.31-lp150.5.3.1
binutils-debugsource-2.31-lp150.5.3.1
binutils-devel-2.31-lp150.5.3.1
binutils-gold-2.31-lp150.5.3.1
binutils-gold-debuginfo-2.31-lp150.5.3.1
- openSUSE Leap 15.0 (x86_64):
binutils-devel-32bit-2.31-lp150.5.3.1
cross-aarch64-binutils-2.31-lp150.5.3.1
cross-aarch64-binutils-debuginfo-2.31-lp150.5.3.1
cross-aarch64-binutils-debugsource-2.31-lp150.5.3.1
cross-arm-binutils-2.31-lp150.5.3.1
cross-arm-binutils-debuginfo-2.31-lp150.5.3.1
cross-arm-binutils-debugsource-2.31-lp150.5.3.1
cross-avr-binutils-2.31-lp150.5.3.1
cross-avr-binutils-debuginfo-2.31-lp150.5.3.1
cross-avr-binutils-debugsource-2.31-lp150.5.3.1
cross-epiphany-binutils-2.31-lp150.5.3.1
cross-epiphany-binutils-debuginfo-2.31-lp150.5.3.1
cross-epiphany-binutils-debugsource-2.31-lp150.5.3.1
cross-hppa-binutils-2.31-lp150.5.3.1
cross-hppa-binutils-debuginfo-2.31-lp150.5.3.1
cross-hppa-binutils-debugsource-2.31-lp150.5.3.1
cross-hppa64-binutils-2.31-lp150.5....
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2017-15938.html
https://www.suse.com/security/cve/CVE-2017-15939.html
https://www.suse.com/security/cve/CVE-2017-15996.html
https://www.suse.com/security/cve/CVE-2017-16826.html
https://www.suse.com/security/cve/CVE-2017-16827.html
https://www.suse.com/security/cve/CVE-2017-16828.html
https://www.suse.com/security/cve/CVE-2017-16829.html
https://www.suse.com/security/cve/CVE-2017-16830.html
https://www.suse.com/security/cve/CVE-2017-16831.html
https://www.suse.com/security/cve/CVE-2017-16832.html
https://www.suse.com/security/cve/CVE-2018-10372.html
https://www.suse.com/security/cve/CVE-2018-10373.html
https://www.suse.com/security/cve/CVE-2018-10534.html
https://www.suse.com/security/cve/CVE-2018-10535.html
https://www.suse.com/security/cve/CVE-2018-6323.html
https://www.suse.com/security/cve/CVE-2018-6543.html
https://www.suse.com/security/cve/CVE-2018-6759.html
https://www.suse.com/security/cve/CVE-2018-6872.html
https://www.suse.com/security/cve/CVE-2018-7208.ht...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.