CLSA-2023-1687795384
Dashboard / Vulnerabilities / CLSA-2023-1687795384
CLSA-2023-1687795384
Summary: Fix CVE(s): CVE-2023-25584, CVE-2017-12450, CVE-2023-25588, CVE-2023-25585
Details: * SECURITY UPDATE: fixing the existing CVE-2017-12450 patches that were incorrectly ported from upstream - debian/patches/CVE-2017-12450-1.patch: fix address violation errors - debian/patches/CVE-2017-12450-2.patch: import patches from mainline to fix minor binutils bugs - CVE-2017-12450 * SECURITY UPDATE: heap-based buffer overflow - debian/patches/CVE-2023-25584.patch: lack of bounds checking in vms-alpha.c - CVE-2023-25584 * SECURITY UPDATE: segmentation fault due to uninitialized - debian/patches/CVE-2023-25585.patch: field file_table of struct module is uninitialized - CVE-2023-25585 * SECURITY UPDATE: segmentation fault due to uninitialized - debian/patches/CVE-2023-25588.patch: field `the_bfd` of `asymbol` is uninitialised - CVE-2023-25588 * Fix memory leaks and buffer overflow in vms-alpha.c - debian/patches/vms-alpha-buffer-overflow-fix.patch: fix heap-based buffer overflow in build_module_list in vms-alpha.c - debian/patches/vms-alpha-memory-leaks-fix.patch: fix memory leaks and buffer overflow in vms-alpha.c
Affected packages
Package
Name: binutils
Purl: pkg:deb/tuxcare/binutils?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
