Oval Definition:oval:com.redhat.rhsa:def:20193575
Revision Date:2019-11-05Version:636
Title:RHSA-2019:3575: elfutils security, bug fix, and enhancement update (Low)
Description:The elfutils packages contain a number of utility programs and libraries related to the creation and maintenance of executable code.

  • The following packages have been upgraded to a later upstream version: elfutils (0.176). (BZ#1683705)

    Security Fix(es):

  • elfutils: buffer over-read in the ebl_object_note function in eblobjnote.c in libebl (CVE-2019-7146)

  • elfutils: heap-based buffer over-read in read_srclines in dwarf_getsrclines.c in libdw (CVE-2019-7149)

  • elfutils: segmentation fault in elf64_xlatetom in libelf/elf32_xlatetom.c (CVE-2019-7150)

  • elfutils: out of bound write in elf_cvt_note in libelf/note_xlate.h (CVE-2019-7664)

  • elfutils: heap-based buffer over-read in function elf32_xlatetom in elf32_xlatetom.c (CVE-2019-7665)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2019-7146
    CVE-2019-7149
    CVE-2019-7150
    CVE-2019-7664
    CVE-2019-7665
    RHSA-2019:3575
    Platform(s):Red Hat Enterprise Linux 8
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 8 is installed
  • OR Red Hat CoreOS 4 is installed
  • AND
  • elfutils is earlier than 0:0.176-5.el8
  • AND elfutils is signed with Red Hat redhatrelease2 key
  • elfutils-default-yama-scope is earlier than 0:0.176-5.el8
  • AND elfutils-default-yama-scope is signed with Red Hat redhatrelease2 key
  • elfutils-devel is earlier than 0:0.176-5.el8
  • AND elfutils-devel is signed with Red Hat redhatrelease2 key
  • elfutils-devel-static is earlier than 0:0.176-5.el8
  • AND elfutils-devel-static is signed with Red Hat redhatrelease2 key
  • elfutils-libelf is earlier than 0:0.176-5.el8
  • AND elfutils-libelf is signed with Red Hat redhatrelease2 key
  • elfutils-libelf-devel is earlier than 0:0.176-5.el8
  • AND elfutils-libelf-devel is signed with Red Hat redhatrelease2 key
  • elfutils-libelf-devel-static is earlier than 0:0.176-5.el8
  • AND elfutils-libelf-devel-static is signed with Red Hat redhatrelease2 key
  • elfutils-libs is earlier than 0:0.176-5.el8
  • AND elfutils-libs is signed with Red Hat redhatrelease2 key
  • BACK