Revision Date: | 2020-12-01 | Version: | 1 |
Title: | Security update for binutils (Moderate) |
Description: |
This update for binutils fixes the following issues:
binutils was updated to current 2.32 branch @7b468db3 [jsc#ECO-368]:
Includes the following security fixes:
- CVE-2018-17358: Fixed invalid memory access in _bfd_stab_section_find_nearest_line in syms.c (bsc#1109412) - CVE-2018-17359: Fixed invalid memory access exists in bfd_zalloc in opncls.c (bsc#1109413) - CVE-2018-17360: Fixed heap-based buffer over-read in bfd_getl32 in libbfd.c (bsc#1109414) - CVE-2018-17985: Fixed a stack consumption problem caused by the cplus_demangle_type (bsc#1116827) - CVE-2018-18309: Fixed an invalid memory address dereference was discovered in read_reloc in reloc.c (bsc#1111996) - CVE-2018-18483: Fixed get_count function provided by libiberty that allowed attackers to cause a denial of service or other unspecified impact (bsc#1112535) - CVE-2018-18484: Fixed stack exhaustion in the C++ demangling functions provided by libiberty, caused by recursive stack frames (bsc#1112534) - CVE-2018-18605: Fixed a heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup causing a denial of service (bsc#1113255) - CVE-2018-18606: Fixed a NULL pointer dereference in _bfd_add_merge_section when attempting to merge sections with large alignments, causing denial of service (bsc#1113252) - CVE-2018-18607: Fixed a NULL pointer dereference in elf_link_input_bfd when used for finding STT_TLS symbols without any TLS section, causing denial of service (bsc#1113247) - CVE-2018-19931: Fixed a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h (bsc#1118831) - CVE-2018-19932: Fixed an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA (bsc#1118830) - CVE-2018-20623: Fixed a use-after-free in the error function in elfcomm.c (bsc#1121035) - CVE-2018-20651: Fixed a denial of service via a NULL pointer dereference in elf_link_add_object_symbols in elflink.c (bsc#1121034) - CVE-2018-20671: Fixed an integer overflow that can trigger a heap-based buffer overflow in load_specific_debug_section in objdump.c (bsc#1121056) - CVE-2018-1000876: Fixed integer overflow in bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc in objdump (bsc#1120640) - CVE-2019-1010180: Fixed an out of bound memory access that could lead to crashes (bsc#1142772)
- Enable xtensa architecture (Tensilica lc6 and related) - Use -ffat-lto-objects in order to provide assembly for static libs (bsc#1141913). - Fixed some LTO problems (bsc#1133131 bsc#1133232). - riscv: Don't check ABI flags if no code section
Update to binutils 2.32:
The binutils now support for the C-SKY processor series. * The x86 assembler now supports a -mvexwig=[0|1] option to control encoding of VEX.W-ignored (WIG) VEX instructions. It also has a new -mx86-used-note=[yes|no] option to generate (or not) x86 GNU property notes. * The MIPS assembler now supports the Loongson EXTensions R2 (EXT2), the Loongson EXTensions (EXT) instructions, the Loongson Content Address Memory (CAM) ASE and the Loongson MultiMedia extensions Instructions (MMI) ASE. * The addr2line, c++filt, nm and objdump tools now have a default limit on the maximum amount of recursion that is allowed whilst demangling strings. This limit can be disabled if necessary. * Objdump's --disassemble option can now take a parameter, specifying the starting symbol for disassembly. Disassembly will continue from this symbol up to the next symbol or the end of the function. * The BFD linker will now report property change in linker map file when merging GNU properties. * The BFD linker's -t option now doesn't report members within archives, unless -t is given twice. This makes it more useful when generating a list of files that should be packaged for a linker bug report. * The GOLD linker has improved warning messages for relocations that refer to discarded sections.
- Improve relro support on s390 [fate#326356] - Handle ELF compressed header alignment correctly.
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1057389 1074171 1075737 1075738 1075739 1075748 1089524 1109412 1109413 1109414 1110850 1111996 1112534 1112535 1112758 1113247 1113252 1113255 1113660 1116827 1118830 1118831 1120640 1120767 1121034 1121035 1121056 1126230 1133131 1133232 1134078 1136082 1136572 1139073 1141035 1141913 1142772 1143194 1143273 1152856 1154043 1154212 1155988 1157607 1161096 1162553 1169659 1170313 1170423 1171670 1171921 1171960 1171961 1171963 1174157 1175259 1178171 1178588 859835 945190 CVE-2014-1624 CVE-2014-3577 CVE-2015-5262 CVE-2017-1000251 CVE-2017-17935 CVE-2018-1000872 CVE-2018-1000876 CVE-2018-11784 CVE-2018-16840 CVE-2018-16842 CVE-2018-17358 CVE-2018-17359 CVE-2018-17360 CVE-2018-17985 CVE-2018-18309 CVE-2018-18483 CVE-2018-18484 CVE-2018-18605 CVE-2018-18606 CVE-2018-18607 CVE-2018-19931 CVE-2018-19932 CVE-2018-20623 CVE-2018-20651 CVE-2018-20671 CVE-2018-5334 CVE-2018-5335 CVE-2018-5336 CVE-2019-1010180 CVE-2019-11135 CVE-2019-11139 CVE-2019-12519 CVE-2019-12520 CVE-2019-12521 CVE-2019-12524 CVE-2019-13057 CVE-2019-13565 CVE-2019-17639 CVE-2019-2894 CVE-2019-2933 CVE-2019-2945 CVE-2019-2949 CVE-2019-2958 CVE-2019-2962 CVE-2019-2964 CVE-2019-2973 CVE-2019-2978 CVE-2019-2981 CVE-2019-2983 CVE-2019-2987 CVE-2019-2988 CVE-2019-2989 CVE-2019-2992 CVE-2019-2999 CVE-2019-6470 CVE-2020-10753 CVE-2020-11945 CVE-2020-14577 CVE-2020-14578 CVE-2020-14579 CVE-2020-14583 CVE-2020-14593 CVE-2020-14621 CVE-2020-26950 SUSE-SU-2017:2523-1 SUSE-SU-2018:0191-1 SUSE-SU-2018:3608-1 SUSE-SU-2019:0391-1 SUSE-SU-2019:2650-1 SUSE-SU-2019:3084-1 SUSE-SU-2020:1227-1 SUSE-SU-2020:1748-1 SUSE-SU-2020:2482-1 SUSE-SU-2020:3149-1 SUSE-SU-2020:3331-1
|
Platform(s): | openSUSE Leap 15.1 SUSE Linux Enterprise Server 12 SP3 SUSE Linux Enterprise Server 12 SP3-BCL SUSE Linux Enterprise Server 12 SP3-ESPOS SUSE Linux Enterprise Server 12 SP3-LTSS SUSE Linux Enterprise Server 12 SP3-TERADATA SUSE Linux Enterprise Server 12 SP4 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud Crowbar 9
| Product(s): | |
Definition Synopsis |
openSUSE Leap 15.1 is installed AND Package Information
exempi-2.4.5-lp151.3.3 is installed
OR exempi-tools-2.4.5-lp151.3.3 is installed
OR libexempi-devel-2.4.5-lp151.3.3 is installed
OR libexempi3-2.4.5-lp151.3.3 is installed
OR libexempi3-32bit-2.4.5-lp151.3.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3 is installed
AND Package Information
kernel-default-4.4.82-6.6 is installed
OR kernel-default-base-4.4.82-6.6 is installed
OR kernel-default-devel-4.4.82-6.6 is installed
OR kernel-default-man-4.4.82-6.6 is installed
OR kernel-devel-4.4.82-6.6 is installed
OR kernel-macros-4.4.82-6.6 is installed
OR kernel-source-4.4.82-6.6 is installed
OR kernel-syms-4.4.82-6.6 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-BCL is installed
AND squid-3.5.21-26.23 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
AND ucode-intel-20191112-13.53 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-LTSS is installed
AND Package Information
java-1_7_0-openjdk-1.7.0.241-43.30 is installed
OR java-1_7_0-openjdk-demo-1.7.0.241-43.30 is installed
OR java-1_7_0-openjdk-devel-1.7.0.241-43.30 is installed
OR java-1_7_0-openjdk-headless-1.7.0.241-43.30 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
AND Package Information
tomcat-8.0.53-29.16 is installed
OR tomcat-admin-webapps-8.0.53-29.16 is installed
OR tomcat-docs-webapp-8.0.53-29.16 is installed
OR tomcat-el-3_0-api-8.0.53-29.16 is installed
OR tomcat-javadoc-8.0.53-29.16 is installed
OR tomcat-jsp-2_3-api-8.0.53-29.16 is installed
OR tomcat-lib-8.0.53-29.16 is installed
OR tomcat-servlet-3_1-api-8.0.53-29.16 is installed
OR tomcat-webapps-8.0.53-29.16 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP4 is installed
AND clamav-0.100.2-33.18 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud Crowbar 8 is installed
AND binutils-2.32-9.33 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud Crowbar 9 is installed
AND nodejs6-6.17.1-11.37 is installed
|