Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE: 2021:4572-1 Moderate: glibc Denial of Service

opensuse
Calendar Grey October 23, 2018
Dist Opensuse Esm H88
openSUSE Security Update: Security update for binutils Announcement ID: openSUSE-SU-2018:3323-1 Rati
An update that solves 25 vulnerabilities and has two fixes is now available.

Description

This update for binutils to version 2.31 fixes the following issues:

These security issues were fixed:

- CVE-2017-15996: readelf allowed remote attackers to cause a denial of

service (excessive memory allocation) or possibly have unspecified other

impact via a crafted ELF file that triggered a buffer overflow on fuzzed

archive header (bsc#1065643)

- CVE-2017-15939: Binary File Descriptor (BFD) library (aka libbfd)

mishandled NULL files in a .debug_line file table, which allowed remote

attackers to cause a denial of service (NULL pointer dereference and

application crash) via a crafted ELF file, related to concat_filename

(bsc#1065689)

- CVE-2017-15938: the Binary File Descriptor (BFD) library (aka libbfd)

miscalculated DW_FORM_ref_addr die refs in the case of a relocatable

object file, which allowed remote attackers to cause a denial of service

(find_abstract_instance_name invalid memory read, segmentation fault,

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-1222=1

Package List

- openSUSE Leap 15.0 (i586 x86_64):

binutils-2.31-lp150.5.3.1

binutils-debuginfo-2.31-lp150.5.3.1

binutils-debugsource-2.31-lp150.5.3.1

binutils-devel-2.31-lp150.5.3.1

binutils-gold-2.31-lp150.5.3.1

binutils-gold-debuginfo-2.31-lp150.5.3.1

- openSUSE Leap 15.0 (x86_64):

binutils-devel-32bit-2.31-lp150.5.3.1

cross-aarch64-binutils-2.31-lp150.5.3.1

cross-aarch64-binutils-debuginfo-2.31-lp150.5.3.1

cross-aarch64-binutils-debugsource-2.31-lp150.5.3.1

cross-arm-binutils-2.31-lp150.5.3.1

cross-arm-binutils-debuginfo-2.31-lp150.5.3.1

cross-arm-binutils-debugsource-2.31-lp150.5.3.1

cross-avr-binutils-2.31-lp150.5.3.1

cross-avr-binutils-debuginfo-2.31-lp150.5.3.1

cross-avr-binutils-debugsource-2.31-lp150.5.3.1

cross-epiphany-binutils-2.31-lp150.5.3.1

cross-epiphany-binutils-debuginfo-2.31-lp150.5.3.1

cross-epiphany-binutils-debugsource-2.31-lp150.5.3.1

cross-hppa-binutils-2.31-lp150.5.3.1

cross-hppa-binutils-debuginfo-2.31-lp150.5.3.1

cross-hppa-binutils-debugsource-2.31-lp150.5.3.1

cross-hppa64-binutils-2.31-lp150.5....

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2017-15938.html

https://www.suse.com/security/cve/CVE-2017-15939.html

https://www.suse.com/security/cve/CVE-2017-15996.html

https://www.suse.com/security/cve/CVE-2017-16826.html

https://www.suse.com/security/cve/CVE-2017-16827.html

https://www.suse.com/security/cve/CVE-2017-16828.html

https://www.suse.com/security/cve/CVE-2017-16829.html

https://www.suse.com/security/cve/CVE-2017-16830.html

https://www.suse.com/security/cve/CVE-2017-16831.html

https://www.suse.com/security/cve/CVE-2017-16832.html

https://www.suse.com/security/cve/CVE-2018-10372.html

https://www.suse.com/security/cve/CVE-2018-10373.html

https://www.suse.com/security/cve/CVE-2018-10534.html

https://www.suse.com/security/cve/CVE-2018-10535.html

https://www.suse.com/security/cve/CVE-2018-6323.html

https://www.suse.com/security/cve/CVE-2018-6543.html

https://www.suse.com/security/cve/CVE-2018-6759.html

https://www.suse.com/security/cve/CVE-2018-6872.html

https://www.suse.com/security/cve/CVE-2018-7208.ht...

Read the Full Advisory

Announcement ID: openSUSE-SU-2018:3323-1
Rating: moderate
Affected Products: openSUSE Leap 15.0 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here