Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
198

Arch Linux ASA-201606-23 High Severity: Libdwarf Arbitrary Code Execution

The package libdwarf before version 20160613-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-201606-23 ========================================= Severity: High Date : 2016-06-25 CVE-ID : CVE-2016-5027 CVE-2016-5028 CVE-2016-5029 CVE-2016-5030 CVE-2016-5031 CVE-2016-5032 CVE-2016-5033 CVE-2016-5034 CVE-2016-5035 CVE-2016-5036 CVE-2016-5037 CVE-2016-5038 CVE-2016-5039 CVE-2016-5040 CVE-2016-5041 CVE-2016-5042 CVE-2016-5043 CVE-2016-5044 Package : libdwarf Type : arbitrary code execution Remote : No Link : https://wiki.archlinux.org/title/CVE Summary ====== The package libdwarf before version 20160613-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 20160613-1. # pacman -Syu "libdwarf> =20160613-1" The problems have been fixed upstream in version 20160613. Workaround ========= None. Description ========== - CVE-2016-5027 (denial of service) Multiple NULL pointer dereference issues in several functions of libdwarf/dwarf_leb.c, where leb128_length was wrongly assumed non-NULL. - CVE-2016-5028 (denial of service) NULL pointer dereference issue in print_frame_inst_bytes(). - CVE-2016-5029 (denial of service) NULL pointer dereference issue in create_fullest_file_path(). - CVE-2016-5030 (denial of service) NULL pointer dereference issue in _dwarf_calculate_info_section_end_ptr(). - CVE-2016-5031 (denial of service) Out-of-bounds read bug in print_frame_inst_bytes(). - CVE-2016-5032 (denial of service) Out-of-bounds read bug in dwarf_get_xu_hash_entry(). - CVE-2016-5033 (denial of service) Out-of-bounds read bug in print_exprloc_content(). - CVE-2016-5034 (arbitrary code execution) Invalid write in dwarf_elf_access.c. - CVE-2016-5035 (denial of service) Out-of-bounds read bug in _dwarf_read_line_table_header(). - CVE-2016-5036 (denial of service) Out-of-bounds read bug in dump_block(). - CVE-2016-5037 (denial ofservice) NULL pointer dereference issue in _dwarf_load_section(). - CVE-2016-5038 (denial of service) NULL pointer dereference issue in dwarf_get_macro_startend_file(). - CVE-2016-5039 (denial of service) Out-of-bounds read bug in get_attr_value(). - CVE-2016-5040 (denial of service) Out-of-bounds read bug. - CVE-2016-5041 (denial of service) NULL pointer dereference issue. - CVE-2016-5042 (denial of service) Infinite loop leading to out-of-bounds read in dwarf_get_aranges_list(). - CVE-2016-5043 (denial of service) Out-of-bounds read bug in dwarf_dealloc(). - CVE-2016-5044 (arbitrary code execution) Heap-overflow. Impact ===== An attacker might be able to execute arbitrary code on the affected host with a crafted ELF file, or crafted dwarf sections in a object file. References ========= https://seclists.org/oss-sec/2016/q2/393 https://www.prevanders.net/dwarfbug.html https://access.redhat.com/security/cve/CVE-2016-5027 https://access.redhat.com/security/cve/CVE-2016-5028 https://access.redhat.com/security/cve/CVE-2016-5029 https://access.redhat.com/security/cve/CVE-2016-5030 https://access.redhat.com/security/cve/CVE-2016-5031 https://access.redhat.com/security/cve/CVE-2016-5032 https://access.redhat.com/security/cve/CVE-2016-5033 https://access.redhat.com/security/cve/CVE-2016-5034 https://access.redhat.com/security/cve/CVE-2016-5035 https://access.redhat.com/security/cve/CVE-2016-5036 https://access.redhat.com/security/cve/CVE-2016-5037 https://access.redhat.com/security/cve/CVE-2016-5038 https://access.redhat.com/security/cve/CVE-2016-5039 https://access.redhat.com/security/cve/CVE-2016-5040 https://access.redhat.com/security/cve/CVE-2016-5041 https://access.redhat.com/security/cve/CVE-2016-5042 https://access.redhat.com/security/cve/CVE-2016-5043 https://access.redhat.com/security/cve/CVE-2016-5044 . Update libdwarf to mitigate a critical vulnerability that allows arbitrary code execution on Arch Linux; comprehensive effectsand solutions are outlined.. libdwarf, Arbitrary Code Execution, Arch Linux Update, System Security. . LinuxSecurity.com Team

Calendar 2 Jun 25, 2016 ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here