You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa elfutils

Sigurnosni nedostaci programskog paketa elfutils

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2019-44a9d99647
2019-02-18 02:03:22.662227
——————————————————————————–

Name : elfutils
Product : Fedora 29
Version : 0.176
Release : 1.fc29
URL : http://elfutils.org/
Summary : A collection of utilities and DSOs to handle ELF files and DWARF data
Description :
Elfutils is a collection of utilities, including stack (to show
backtraces), nm (for listing symbols from object files), size
(for listing the section sizes of an object or archive file),
strip (for discarding symbols), readelf (to see the raw ELF file
structures), elflint (to check for well-formed ELF files) and
elfcompress (to compress or decompress ELF sections).

——————————————————————————–
Update Information:

New upstream release 0.176. Fixes CVE-2019-7146, CVE-2019-7148, CVE-2019-7149,
CVE-2019-7150, CVE-2019-7664 and CVE-2019-7665.
——————————————————————————–
ChangeLog:

* Fri Feb 15 2019 Mark Wielaard <mjw@fedoraproject.org> – 0.176-1
– New upstream release.
– backends: riscv improved core file and return value location support.
– Fixes CVE-2019-7146, CVE-2019-7148, CVE-2019-7149, CVE-2019-7150,
CVE-2019-7664, CVE-2019-7665.
* Thu Jan 31 2019 Fedora Release Engineering <releng@fedoraproject.org> – 0.175-3
– Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Mon Dec 3 2018 Mark Wielaard <mjw@fedoraproject.org> – 0.175-2
– Add elfutils-0.175-gnu-props-32.patch.
* Fri Nov 16 2018 Mark Wielaard <mjw@fedoraproject.org> – 0.175-1
– New upstream release.
– readelf: Handle multiple .debug_macro sections.
– strip: Add strip –reloc-debug-sections-only option.
Handle relocations against GNU compressed sections.
– libdwelf: New function dwelf_elf_begin.
– libcpu: Recognize bpf jump variants BPF_JLT, BPF_JLE, BPF_JSLT
and BPF_JSLE.
– backends: RISCV handles ADD/SUB relocations.
– Remove all patches.
* Wed Nov 14 2018 Mark Wielaard <mjw@fedoraproject.org> – 0.174-5
– Add elfutils-0.174-x86_64_unwind.patch.
– Add elfutils-0.174-gnu-property-note.patch.
– Add elfutils-0.174-version-note.patch.
– Add elfutils-0.174-gnu-attribute-note.patch
* Tue Nov 6 2018 Mark Wielaard <mjw@fedoraproject.org> – 0.174-4
– Add elfutils-0.174-size-rec-ar.patch
CVE-2018-18520 (#1646478)
– Add elfutils-0.174-ar-sh_entsize-zero.patch
CVE-2018-18521 (#1646483)
* Fri Nov 2 2018 Mark Wielaard <mjw@fedoraproject.org> – 0.174-3
– Add elfutils-0.174-libdwfl-sanity-check-core-reads.patch
CVE-2018-18310 (#1642605)
* Wed Oct 17 2018 Mark Wielaard <mjw@fedoraproject.org> – 0.174-2
– Add elfutils-0.174-strip-unstrip-group.patch.
——————————————————————————–
References:

[ 1 ] Bug #1671433 – CVE-2019-7146 elfutils: buffer over-read in the ebl_object_note function in eblobjnote.c in libebl [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1671433
[ 2 ] Bug #1671444 – CVE-2019-7149 elfutils: heap-based buffer over-read in read_srclines in dwarf_getsrclines.c in libdw [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1671444
[ 3 ] Bug #1677537 – CVE-2019-7664 elfutils: Out of bound write in elf_cvt_note in libelf/note_xlate.h [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1677537
[ 4 ] Bug #1677539 – CVE-2019-7665 elfutils: heap-based buffer over-read in function elf32_xlatetom in elf32_xlatetom.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1677539
[ 5 ] Bug #1677717 – elfutils-0.176 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1677717
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2019-44a9d99647’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

AutorToni Vugdelija
Cert idNCERT-REF-2019-02-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa ghostscript

Otkriveni su sigurnosni nedostaci u programskom paketu ghostscript za operacijski sustav Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju izazivanje DoS stanja,...

Close