SUSE-SU-2019:1486-1
Dashboard / Vulnerabilities / SUSE-SU-2019:1486-1
SUSE-SU-2019:1486-1
Summary: Security update for elfutils
Details: This update for elfutils fixes the following issues: Security issues fixed: - CVE-2017-7607: Fixed a heap-based buffer overflow in handle_gnu_hash (bsc#1033084) - CVE-2017-7608: Fixed a heap-based buffer overflow in ebl_object_note_type_name() (bsc#1033085) - CVE-2017-7609: Fixed a memory allocation failure in __libelf_decompress (bsc#1033086) - CVE-2017-7610: Fixed a heap-based buffer overflow in check_group (bsc#1033087) - CVE-2017-7611: Fixed a denial of service via a crafted ELF file (bsc#1033088) - CVE-2017-7612: Fixed a denial of service in check_sysv_hash() via a crafted ELF file (bsc#1033089) - CVE-2017-7613: Fixed denial of service caused by the missing validation of the number of sections and the number of segments in a crafted ELF file (bsc#1033090) - CVE-2018-16062: Fixed a heap-buffer overflow in /elfutils/libdw/dwarf_getaranges.c:156 (bsc#1106390) - CVE-2018-16402: Fixed a denial of service/double free on an attempt to decompress the same section twice (bsc#1107066) - CVE-2018-16403: Fixed a heap buffer overflow in readelf (bsc#1107067) - CVE-2018-18310: Fixed an invalid address read problem in dwfl_segment_report_module.c (bsc#1111973) - CVE-2018-18520: Fixed bad handling of ar files inside are files (bsc#1112726) - CVE-2018-18521: Fixed a denial of service vulnerabilities in the function arlib_add_symbols() used by eu-ranlib (bsc#1112723) - CVE-2019-7150: dwfl_segment_report_module doesn't check whether the dyn data read from core file is truncated (bsc#1123685) - CVE-2019-7665: NT_PLATFORM core file note should be a zero terminated string (bsc#1125007)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20191486-1/, https://bugzilla.suse.com/1033084, https://bugzilla.suse.com/1033085, https://bugzilla.suse.com/1033086, https://bugzilla.suse.com/1033087, https://bugzilla.suse.com/1033088, https://bugzilla.suse.com/1033089, https://bugzilla.suse.com/1033090, https://bugzilla.suse.com/1106390, https://bugzilla.suse.com/1107066, https://bugzilla.suse.com/1107067, https://bugzilla.suse.com/1111973, https://bugzilla.suse.com/1112723, https://bugzilla.suse.com/1112726, https://bugzilla.suse.com/1123685, https://bugzilla.suse.com/1125007, https://www.suse.com/security/cve/CVE-2017-7607, https://www.suse.com/security/cve/CVE-2017-7608, https://www.suse.com/security/cve/CVE-2017-7609, https://www.suse.com/security/cve/CVE-2017-7610, https://www.suse.com/security/cve/CVE-2017-7611, https://www.suse.com/security/cve/CVE-2017-7612, https://www.suse.com/security/cve/CVE-2017-7613, https://www.suse.com/security/cve/CVE-2018-16062, https://www.suse.com/security/cve/CVE-2018-16402, https://www.suse.com/security/cve/CVE-2018-16403, https://www.suse.com/security/cve/CVE-2018-18310, https://www.suse.com/security/cve/CVE-2018-18520, https://www.suse.com/security/cve/CVE-2018-18521, https://www.suse.com/security/cve/CVE-2019-7150, https://www.suse.com/security/cve/CVE-2019-7665
Affected packages
Package
Name: elfutils
Purl: pkg:rpm/suse/elfutils&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
Affected ranges
Type: ECOSYSTEM
Events:
