drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in elfutils
Name: |
Mehrere Probleme in elfutils |
|
ID: |
FEDORA-2018-32c8599fe1 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 29 |
|
Datum: |
Mo, 1. Oktober 2018, 06:33 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16403
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16402
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16062 |
|
Applikationen: |
elfutils |
|
Originalnachricht |
------------------------------------------------------------------------------- - Fedora Update Notification FEDORA-2018-32c8599fe1 2018-09-30 23:24:18.220857 ------------------------------------------------------------------------------- -
Name : elfutils Product : Fedora 29 Version : 0.174 Release : 1.fc29 URL : http://elfutils.org/ Summary : A collection of utilities and DSOs to handle ELF files and DWARF data Description : Elfutils is a collection of utilities, including stack (to show backtraces), nm (for listing symbols from object files), size (for listing the section sizes of an object or archive file), strip (for discarding symbols), readelf (to see the raw ELF file structures), elflint (to check for well-formed ELF files) and elfcompress (to compress or decompress ELF sections).
------------------------------------------------------------------------------- - Update Information:
Fixes CVE-2018-16062, CVE-2018-16402 and CVE-2018-16403. unstrip: Handle SHT_GROUP sections. strip: Handle mixed (out of order) allocated/non-allocated sections. elfcompress: Don't rewrite input file if no section data needs updating. Try harder to keep same file mode bits (suid) on rewrite. libelf, libdw and all tools now handle extended shnum and shstrndx correctly. ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #1625050 - CVE-2018-16402 elfutils: Double-free due to double decompression of sections in crafted ELF causes crash https://bugzilla.redhat.com/show_bug.cgi?id=1625050 [ 2 ] Bug #1625055 - CVE-2018-16403 elfutils: Heap-based buffer over-read in libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash https://bugzilla.redhat.com/show_bug.cgi?id=1625055 [ 3 ] Bug #1623752 - CVE-2018-16062 elfutils: Heap-based buffer over-read in libdw/dwarf_getaranges.c:dwarf_getaranges() via crafted file https://bugzilla.redhat.com/show_bug.cgi?id=1623752 ------------------------------------------------------------------------------- -
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-32c8599fe1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
|
|
|
|