Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in elfutils
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in elfutils
ID: FEDORA-2018-32c8599fe1
Distribution: Fedora
Plattformen: Fedora 29
Datum: Mo, 1. Oktober 2018, 06:33
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16403
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16402
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16062
Applikationen: elfutils

Originalnachricht

-------------------------------------------------------------------------------
-
Fedora Update Notification
FEDORA-2018-32c8599fe1
2018-09-30 23:24:18.220857
-------------------------------------------------------------------------------
-

Name : elfutils
Product : Fedora 29
Version : 0.174
Release : 1.fc29
URL : http://elfutils.org/
Summary : A collection of utilities and DSOs to handle ELF files and DWARF
data
Description :
Elfutils is a collection of utilities, including stack (to show
backtraces), nm (for listing symbols from object files), size
(for listing the section sizes of an object or archive file),
strip (for discarding symbols), readelf (to see the raw ELF file
structures), elflint (to check for well-formed ELF files) and
elfcompress (to compress or decompress ELF sections).

-------------------------------------------------------------------------------
-
Update Information:

Fixes CVE-2018-16062, CVE-2018-16402 and CVE-2018-16403. unstrip: Handle
SHT_GROUP sections. strip: Handle mixed (out of order) allocated/non-allocated
sections. elfcompress: Don't rewrite input file if no section data needs
updating. Try harder to keep same file mode bits (suid) on rewrite. libelf,
libdw and all tools now handle extended shnum and shstrndx correctly.
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1625050 - CVE-2018-16402 elfutils: Double-free due to double
decompression of sections in crafted ELF causes crash
https://bugzilla.redhat.com/show_bug.cgi?id=1625050
[ 2 ] Bug #1625055 - CVE-2018-16403 elfutils: Heap-based buffer over-read in
libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash
https://bugzilla.redhat.com/show_bug.cgi?id=1625055
[ 3 ] Bug #1623752 - CVE-2018-16062 elfutils: Heap-based buffer over-read in
libdw/dwarf_getaranges.c:dwarf_getaranges() via crafted file
https://bugzilla.redhat.com/show_bug.cgi?id=1623752
-------------------------------------------------------------------------------
-

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-32c8599fe1' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung