[CLSA-2023:1701293664] binutils: Fix of 7 CVEs
Type:
security
Severity:
Important
Release date:
2023-11-29
Description:
- CVE-2021-45078: Fix out-of-bounds write in stab_xcoff_builtin_type - CVE-2021-46174: Fix buffer overflow in read_section_stabs_debugging_info - CVE-2022-44840: Fix possible heap buffer overflow in find_section_in_set() in readelf.c - CVE-2022-45703: Combine sanity checks, calculate element counts, not word counts, fix typo - CVE-2022-47695: Test symbol flags to exclude section and synthetic symbols before attempting to check flavour - CVE-2022-47696: Fix uninitialised field `the_bfd` of `asymbol` - CVE-2022-47673: Fix lack of bounds checking in vms-alpha.c
Updated packages:
  • binutils-2.35.2-37.el9.tuxcare.els1.i686.rpm
    sha:222a549ae8ca77a377f54687c8202bb599741f39
  • binutils-2.35.2-37.el9.tuxcare.els1.x86_64.rpm
    sha:5c6177ed0e5593cd6a995c55f54101b8ac3d0062
  • binutils-devel-2.35.2-37.el9.tuxcare.els1.i686.rpm
    sha:ac5b587fecb111b1399cbdcd6392f0901ee8a257
  • binutils-devel-2.35.2-37.el9.tuxcare.els1.x86_64.rpm
    sha:65586c922fc39c40b03cef20ddcc0c5997711a3e
  • binutils-gold-2.35.2-37.el9.tuxcare.els1.x86_64.rpm
    sha:e03bba11b2d24b17de6d891c7c7c66339f97276f
  • cross-binutils-aarch64-2.35.2-37.el9.tuxcare.els1.x86_64.rpm
    sha:e8d12e9a4ef246e80cfe9f697f1dd93c52c98555
  • cross-binutils-ppc64le-2.35.2-37.el9.tuxcare.els1.x86_64.rpm
    sha:771b105df25fcb1a2d246b4ed9daebb2a92fd061
  • cross-binutils-s390x-2.35.2-37.el9.tuxcare.els1.x86_64.rpm
    sha:dce0f08be00221222f404d9095b8e38e7c36428f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.