You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa binutils

Sigurnosni nedostaci programskog paketa binutils

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2019-ba3cbcfd20
2019-02-02 03:34:29.460572
——————————————————————————–

Name : binutils
Product : Fedora 29
Version : 2.31.1
Release : 17.fc29
URL : https://sourceware.org/binutils
Summary : A GNU collection of binary utilities
Description :
Binutils is a collection of binary utilities, including ar (for
creating, modifying and extracting from archives), as (a family of GNU
assemblers), gprof (for displaying call graph profile data), ld (the
GNU linker), nm (for listing symbols from object files), objcopy (for
copying and translating object files), objdump (for displaying
information from object files), ranlib (for generating an index for
the contents of an archive), readelf (for displaying detailed
information about binary files), size (for listing the section sizes
of an object or archive file), strings (for listing printable strings
from files), strip (for discarding symbols), and addr2line (for
converting addresses to file and line).

——————————————————————————–
Update Information:

Bug fixes for binutils including one that is preventing Yocot/oe-core from
building properly
——————————————————————————–
ChangeLog:

* Wed Jan 30 2019 Nick Clifton <nickc@redhat.com> – 2.31.1-17
– Fix the assembler’s check that the output file is not also one of the input files. (#1660279)
* Thu Jan 3 2019 Nick Clifton <nickc@redhat.com> – 2.31.1-16
– Fix a memory leak reading minisymbols. (#1661535)
* Wed Nov 28 2018 Nick Clifton <nickc@redhat.com> – 2.31.1-15
– Stop gold from warning about discard version information unless explicitly requested. (#1654153)
* Thu Nov 15 2018 Nick Clifton <nickc@redhat.com> – 2.31.1-14
– Remove debugging fprintf statement accidentally left in patch. (#1645828)
——————————————————————————–
References:

[ 1 ] Bug #1546608 – ld does not merge .gnu.build.attributes
https://bugzilla.redhat.com/show_bug.cgi?id=1546608
[ 2 ] Bug #1515934 – Mir build fails on ppc64 when LTO is enabled
https://bugzilla.redhat.com/show_bug.cgi?id=1515934
[ 3 ] Bug #1660279 – as from binutils 2.31.1 may fail at some certain condition
https://bugzilla.redhat.com/show_bug.cgi?id=1660279
[ 4 ] Bug #1646536 – CVE-2018-18700 binutils: Recursive Stack Overflow within function d_name, d_encoding, and d_local_name in cp-demangle.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1646536
[ 5 ] Bug #1553086 – gdb: warning: Loadable section “.note.gnu.property” outside of ELF segments
https://bugzilla.redhat.com/show_bug.cgi?id=1553086
[ 6 ] Bug #1483604 – CVE-2017-12448 CVE-2017-12449 CVE-2017-12450 CVE-2017-12451 CVE-2017-12452 CVE-2017-12453 CVE-2017-12454 CVE-2017-12455 CVE-2017-12456 CVE-2017-12457 CVE-2017-12458 CVE-2017-12459 CVE-2017-13710 CVE-2017-13716 binutils: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1483604
[ 7 ] Bug #1639969 – After recent update, gold linker crashes while building chromium with fedora build flags
https://bugzilla.redhat.com/show_bug.cgi?id=1639969
[ 8 ] Bug #1626622 – readelf –unwind not supported
https://bugzilla.redhat.com/show_bug.cgi?id=1626622
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2019-ba3cbcfd20’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

AutorJosip Papratovic
Cert idNCERT-REF-2019-02-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa golang

Otkriveni su sigurnosni nedostaci u programskom paketu golang za operacijski sustav Debian. Otkriveni nedostaci potencijalnim napadačima omogućuju izazivanje DoS stanja...

Close