Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE Linux Enterprise: 2019:2650-1 Moderate: binutils Denial of Service

suse
Calendar Grey October 14, 2019
Dist Suse Esm H88
SUSE releases patches for gcc to resolve various security flaws, improving overall system robustness.
An update that solves 17 vulnerabilities and has three fixes is now available

Summary

This update for binutils fixes the following issues: binutils was updated to current 2.32 branch @7b468db3 [jsc#ECO-368]: Includes the following security fixes: - CVE-2018-17358: Fixed invalid memory access in _bfd_stab_section_find_nearest_line in syms.c (bsc#1109412) - CVE-2018-17359: Fixed invalid memory access exists in bfd_zalloc in opncls.c (bsc#1109413) - CVE-2018-17360: Fixed heap-based buffer over-read in bfd_getl32 in libbfd.c (bsc#1109414) - CVE-2018-17985: Fixed a stack consumption problem caused by the cplus_demangle_type (bsc#1116827) - CVE-2018-18309: Fixed an invalid memory address dereference was discovered in read_reloc in reloc.c (bsc#1111996) - CVE-2018-18483: Fixed get_count function provided by libiberty that

References

#1109412 #1109413 #1109414 #1111996 #1112534

#1112535 #1113247 #1113252 #1113255 #1116827

#1118830 #1118831 #1120640 #1121034 #1121035

#1121056 #1133131 #1133232 #1141913 #1142772

Cross- CVE-2018-1000876 CVE-2018-17358 CVE-2018-17359

CVE-2018-17360 CVE-2018-17985 CVE-2018-18309

CVE-2018-18483 CVE-2018-18484 CVE-2018-18605

CVE-2018-18606 CVE-2018-18607 CVE-2018-19931

CVE-2018-19932 CVE-2018-20623 CVE-2018-20651

CVE-2018-20671 CVE-2019-1010180

Affected Products:

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 8

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Software Development Kit 12-SP5

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Server for SAP 12-SP3

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:2650-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here