Oval Definition:oval:org.opensuse.security:def:63725
Revision Date:2020-12-01Version:1
Title:Security update for elfutils (Low)
Description:

This update for elfutils fixes the following issues:

Security issues fixed:

- CVE-2018-16403: Fixed a heap-based buffer over-read that could have led to Denial of Service (bsc#1107067). - CVE-2016-10254: Fixed a memory allocation failure in alloxate_elf (bsc#1030472). - CVE-2019-7665: NT_PLATFORM core file note should be a zero terminated string (bsc#1125007). - CVE-2016-10255: Fixed a memory allocation failure in libelf_set_rawdata_wrlock (bsc#1030476). - CVE-2019-7150: Added a missing check in dwfl_segment_report_module which could have allowed truncated files to be read (bsc#1123685). - CVE-2018-16062: Fixed a heap-buffer-overflow (bsc#1106390). - CVE-2017-7611: Fixed a heap-based buffer over-read that could have led to Denial of Service (bsc#1033088). - CVE-2017-7613: Fixed denial of service caused by the missing validation of the number of sections and the number of segments in a crafted ELF file (bsc#1033090). - CVE-2017-7607: Fixed a heap-based buffer overflow in handle_gnu_hash (bsc#1033084). - CVE-2017-7608: Fixed a heap-based buffer overflow in ebl_object_note_type_name() (bsc#1033085). - CVE-2017-7610: Fixed a heap-based buffer overflow in check_group (bsc#1033087). - CVE-2018-18521: Fixed multiple divide-by-zero vulnerabilities in function arlib_add_symbols() (bsc#1112723). - CVE-2017-7612: Fixed a denial of service in check_sysv_hash() via a crafted ELF file (bsc#1033089). - CVE-2018-18310: Fixed an invalid address read in dwfl_segment_report_module.c (bsc#1111973). - CVE-2018-18520: Fixed bad handling of ar files inside are files (bsc#1112726).
Family:unixClass:patch
Status:Reference(s):1030472
1030476
1033084
1033085
1033087
1033088
1033089
1033090
1106390
1107067
1111177
1111973
1112723
1112726
1113246
1114710
1121567
1123164
1123685
1125007
1130360
1138572
1144524
1146848
1150733
1154661
1159819
1160968
1162972
1166847
1168669
1169512
1169746
1170908
1171433
1171978
1173022
1174253
1174538
CVE-2016-10254
CVE-2016-10255
CVE-2017-7607
CVE-2017-7608
CVE-2017-7610
CVE-2017-7611
CVE-2017-7612
CVE-2017-7613
CVE-2018-14662
CVE-2018-16062
CVE-2018-16403
CVE-2018-16846
CVE-2018-16881
CVE-2018-16889
CVE-2018-18310
CVE-2018-18520
CVE-2018-18521
CVE-2019-12816
CVE-2019-13456
CVE-2019-17006
CVE-2019-17185
CVE-2019-18218
CVE-2019-3689
CVE-2019-4732
CVE-2019-7150
CVE-2019-7665
CVE-2019-9917
CVE-2020-11800
CVE-2020-12399
CVE-2020-12402
CVE-2020-15652
CVE-2020-15653
CVE-2020-15654
CVE-2020-15655
CVE-2020-15656
CVE-2020-15657
CVE-2020-15658
CVE-2020-15659
CVE-2020-15803
CVE-2020-2583
CVE-2020-2593
CVE-2020-2604
CVE-2020-2659
CVE-2020-6463
CVE-2020-6514
openSUSE-SU-2019:1775-1
openSUSE-SU-2020:0677-1
openSUSE-SU-2020:1189-1
openSUSE-SU-2020:1604-1
SUSE-SU-2019:0209-1
SUSE-SU-2019:0499-1
SUSE-SU-2019:1733-1
SUSE-SU-2019:2781-1
SUSE-SU-2020:0528-1
SUSE-SU-2020:1018-1
SUSE-SU-2020:1839-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-LTSS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • znc-1.7.4-lp151.2.3 is installed
  • OR znc-devel-1.7.4-lp151.2.3 is installed
  • OR znc-lang-1.7.4-lp151.2.3 is installed
  • OR znc-perl-1.7.4-lp151.2.3 is installed
  • OR znc-python3-1.7.4-lp151.2.3 is installed
  • OR znc-tcl-1.7.4-lp151.2.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • MozillaFirefox-78.1.0-lp152.2.15 is installed
  • OR MozillaFirefox-branding-upstream-78.1.0-lp152.2.15 is installed
  • OR MozillaFirefox-buildsymbols-78.1.0-lp152.2.15 is installed
  • OR MozillaFirefox-devel-78.1.0-lp152.2.15 is installed
  • OR MozillaFirefox-translations-common-78.1.0-lp152.2.15 is installed
  • OR MozillaFirefox-translations-other-78.1.0-lp152.2.15 is installed
  • OR gstreamer-plugin-pipewire-0.3.6-lp152.2.3 is installed
  • OR libpipewire-0_3-0-0.3.6-lp152.2.3 is installed
  • OR pipewire-0.3.6-lp152.2.3 is installed
  • OR pipewire-devel-0.3.6-lp152.2.3 is installed
  • OR pipewire-doc-0.3.6-lp152.2.3 is installed
  • OR pipewire-libjack-0_3-0.3.6-lp152.2.3 is installed
  • OR pipewire-libpulse-0_3-0.3.6-lp152.2.3 is installed
  • OR pipewire-modules-0.3.6-lp152.2.3 is installed
  • OR pipewire-spa-plugins-0_2-0.3.6-lp152.2.3 is installed
  • OR pipewire-spa-tools-0.3.6-lp152.2.3 is installed
  • OR pipewire-tools-0.3.6-lp152.2.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • elfutils-0.158-7.7 is installed
  • OR libasm1-0.158-7.7 is installed
  • OR libasm1-32bit-0.158-7.7 is installed
  • OR libdw1-0.158-7.7 is installed
  • OR libdw1-32bit-0.158-7.7 is installed
  • OR libebl1-0.158-7.7 is installed
  • OR libebl1-32bit-0.158-7.7 is installed
  • OR libelf-devel-0.158-7.7 is installed
  • OR libelf1-0.158-7.7 is installed
  • OR libelf1-32bit-0.158-7.7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • libfreebl3-3.53.1-58.48 is installed
  • OR libfreebl3-32bit-3.53.1-58.48 is installed
  • OR libfreebl3-hmac-3.53.1-58.48 is installed
  • OR libfreebl3-hmac-32bit-3.53.1-58.48 is installed
  • OR libsoftokn3-3.53.1-58.48 is installed
  • OR libsoftokn3-32bit-3.53.1-58.48 is installed
  • OR libsoftokn3-hmac-3.53.1-58.48 is installed
  • OR libsoftokn3-hmac-32bit-3.53.1-58.48 is installed
  • OR mozilla-nspr-4.25-19.15 is installed
  • OR mozilla-nspr-32bit-4.25-19.15 is installed
  • OR mozilla-nspr-devel-4.25-19.15 is installed
  • OR mozilla-nss-3.53.1-58.48 is installed
  • OR mozilla-nss-32bit-3.53.1-58.48 is installed
  • OR mozilla-nss-certs-3.53.1-58.48 is installed
  • OR mozilla-nss-certs-32bit-3.53.1-58.48 is installed
  • OR mozilla-nss-devel-3.53.1-58.48 is installed
  • OR mozilla-nss-sysinit-3.53.1-58.48 is installed
  • OR mozilla-nss-sysinit-32bit-3.53.1-58.48 is installed
  • OR mozilla-nss-tools-3.53.1-58.48 is installed
  • BACK