Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE Leap: 2019:1590-1 Moderate: Elfutils Multiple Fixes

opensuse
Calendar Grey June 19, 2019
Dist Opensuse Esm H88
A recent openSUSE patch resolves 12 identified vulnerabilities in glibc, ensuring the safety and reliability of the system.
An update that fixes 15 vulnerabilities is now available.

Description

This update for elfutils fixes the following issues:

Security issues fixed:

- CVE-2017-7607: Fixed a heap-based buffer overflow in handle_gnu_hash

(bsc#1033084)

- CVE-2017-7608: Fixed a heap-based buffer overflow in

ebl_object_note_type_name() (bsc#1033085)

- CVE-2017-7609: Fixed a memory allocation failure in __libelf_decompress

(bsc#1033086)

- CVE-2017-7610: Fixed a heap-based buffer overflow in check_group

(bsc#1033087)

- CVE-2017-7611: Fixed a denial of service via a crafted ELF file

(bsc#1033088)

- CVE-2017-7612: Fixed a denial of service in check_sysv_hash() via a

crafted ELF file (bsc#1033089)

- CVE-2017-7613: Fixed denial of service caused by the missing validation

of the number of sections and the number of segments in a crafted ELF

file (bsc#1033090)

- CVE-2018-16062: Fixed a heap-buffer overflow in

/elfutils/libdw/dwarf_getaranges.c:156 (bsc#1106390)

- CVE-2018-16402: Fixed a denial of...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2019-1590=1

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2019-1590=1

Package List

- openSUSE Leap 15.1 (i586 x86_64):

elfutils-0.168-lp151.4.3.1

elfutils-debuginfo-0.168-lp151.4.3.1

elfutils-debugsource-0.168-lp151.4.3.1

libasm-devel-0.168-lp151.4.3.1

libasm1-0.168-lp151.4.3.1

libasm1-debuginfo-0.168-lp151.4.3.1

libdw-devel-0.168-lp151.4.3.1

libdw1-0.168-lp151.4.3.1

libdw1-debuginfo-0.168-lp151.4.3.1

libebl-devel-0.168-lp151.4.3.1

libebl-plugins-0.168-lp151.4.3.1

libebl-plugins-debuginfo-0.168-lp151.4.3.1

libelf-devel-0.168-lp151.4.3.1

libelf1-0.168-lp151.4.3.1

libelf1-debuginfo-0.168-lp151.4.3.1

- openSUSE Leap 15.1 (noarch):

elfutils-lang-0.168-lp151.4.3.1

- openSUSE Leap 15.1 (x86_64):

libasm1-32bit-0.168-lp151.4.3.1

libasm1-32bit-debuginfo-0.168-lp151.4.3.1

libdw1-32bit-0.168-lp151.4.3.1

libdw1-32bit-debuginfo-0.168-lp151.4.3.1

libebl-plugins-32bit-0.168-lp151.4.3.1

libebl-plugins-32bit-debuginfo-0.168-lp151.4.3.1

libelf-devel-32bit-0.168-lp151.4.3.1

libelf1-32bit-0.168-lp151.4.3.1

libelf1-32bit-debuginfo-0.168-lp151.4.3.1

- openSUSE Leap 15.0 (i586 x86_64):

elfutils-0.168-lp150.3.3.1

elfuti...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2017-7607.html

https://www.suse.com/security/cve/CVE-2017-7608.html

https://www.suse.com/security/cve/CVE-2017-7609.html

https://www.suse.com/security/cve/CVE-2017-7610.html

https://www.suse.com/security/cve/CVE-2017-7611.html

https://www.suse.com/security/cve/CVE-2017-7612.html

https://www.suse.com/security/cve/CVE-2017-7613.html

https://www.suse.com/security/cve/CVE-2018-16062.html

https://www.suse.com/security/cve/CVE-2018-16402.html

https://www.suse.com/security/cve/CVE-2018-16403.html

https://www.suse.com/security/cve/CVE-2018-18310.html

https://www.suse.com/security/cve/CVE-2018-18520.html

https://www.suse.com/security/cve/CVE-2018-18521.html

https://www.suse.com/security/cve/CVE-2019-7150.html

https://www.suse.com/security/cve/CVE-2019-7665.html

https://bugzilla.suse.com/1033084

https://bugzilla.suse.com/1033085

https://bugzilla.suse.com/1033086

https://bugzilla.suse.com/1033087

https://bugzilla.suse.com/1033088

https://bugzilla.suse.com/1033089

https://bugzilla...

Read the Full Advisory

Announcement ID: openSUSE-SU-2019:1590-1
Rating: moderate
Affected Products: openSUSE Leap 15.1 openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here