OESA-2021-1098
Dashboard / Vulnerabilities / OESA-2021-1098
Summary: binutils security update
Details: The GNU Binutils are a collection of binary tools. The main ones are: ld - the GNU linker. as - the GNU assembler. addr2line - Converts addresses into filenames and line numbers. ar - A utility for creating, modifying and extracting from archives. c++filt - Filter to demangle encoded C++ symbols. dlltool - Creates files for building and using DLLs. gold - A new, faster, ELF only linker, still in beta test. gprof - Displays profiling information. nlmconv - Converts object code into an NLM. nm - Lists symbols from object files. objcopy - Copies and translates object files. objdump - Displays information from object files. ranlib - Generates an index to the contents of an archive. readelf - Displays information from any ELF format object file. size - Lists the section sizes of an object or archive file. strings - Lists printable strings from files. trip - Discards symbols. windmc - A Windows compatible message compiler. windres - A compiler for Windows resource files. Security Fix(es): Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. The list of affected products is provided in intel-sa-00334: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00334.html(CVE-2020-0551) A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.(CVE-2020-16592)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1098, https://nvd.nist.gov/vuln/detail/CVE-2020-0551, https://nvd.nist.gov/vuln/detail/CVE-2020-16592
Affected packages
Package
Name: binutils
Purl: pkg:rpm/openEuler/binutils&distro=openEuler-20.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
