[CLSA-2023:1696351606] Fix CVE(s): CVE-2020-19724, CVE-2020-19726, CVE-2020-21490, CVE-2020-35342
Type:
security
Severity:
Important
Release date:
2023-10-03 16:46:50 UTC
Description:
* SECURITY UPDATE: uninitialized-heap vulnerability in function tic4x_print_cond in file opcodes/tic4x-dis.c - debian/patches/CVE-2020-35342.patch: Init all of condtable - CVE-2020-35342 * SECURITY UPDATE: a memory consumption issue in get_data function in binutils/nm.c - debian/patches/CVE-2020-19724.patch: Free dyn_syms - CVE-2020-19724 * SECURITY UPDATE: a memory leak when process microblaze-dis.c - debian/patches/CVE-2020-21490.patch: Use strbuf rather than strdup of local temp - CVE-2020-21490 * SECURITY UPDATE: an issue relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service - debian/patches/CVE-2020-19726.patch: Fix parsing a corrupt PE format file - CVE-2020-19726
Updated packages:
  • binutils_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:d2f6fb20fd7ecc7a9221717c02e40a89f83f6fd9
  • binutils-aarch64-linux-gnu_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:3920b67c928993a0ca377aac155225b41909384a
  • binutils-alpha-linux-gnu_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:a6132ab98fe76399e983b0d797588a7da2936e50
  • binutils-arm-linux-gnueabi_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:0627d56a531431727ad9fb7f3972cd929391f6fc
  • binutils-arm-linux-gnueabihf_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:f9aba2aaef0f15cc67de82b43a0ec1772685aff7
  • binutils-dev_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:42373ad502a730291d6c28a1b603c4fcc8486d9e
  • binutils-doc_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_all.deb
    sha:98b2ab3d51ccec73b58f48234c7f5b2005613b19
  • binutils-hppa-linux-gnu_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:6892c248bf494bd68488260e25bf96f77171585e
  • binutils-hppa64-linux-gnu_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:04851183a5d72e1b4cd67d3b28c790380638ddf3
  • binutils-m68k-linux-gnu_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:7e7be457a66ee3e8bb370829266a3f8e6291a99a
  • binutils-mips-linux-gnu_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:c009f688e4a7ea09f54f78c99d29b40f967b77fd
  • binutils-mips64-linux-gnuabi64_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:a0332b9e4938ebf9adb73a6379f36c89638254b6
  • binutils-mips64el-linux-gnuabi64_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:39d1dede5c93a695ce74f2a6fc7c114f11fc6580
  • binutils-mipsel-linux-gnu_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:67c0c89e2b6f5c97da8356639bccf832a5478cbc
  • binutils-multiarch_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:36f1ad50bfbc1f7e9d2a9167f757061d38677ad3
  • binutils-multiarch-dev_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:b848b7d7cea80f9d7f21b71e5eca9826f9bec94f
  • binutils-powerpc-linux-gnu_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:47ccbb4e91b88132d4f614e8f9a9c4f001f1b94f
  • binutils-powerpc-linux-gnuspe_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:fd28b1e08de69ca5f8541b0bb4eebe34ca4768d7
  • binutils-powerpc64-linux-gnu_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:afa2c76221326354ac13ed117b638a4d7c94fb8a
  • binutils-powerpc64le-linux-gnu_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:7505f7c9dca4e21beae2f9ff90b86e2b9ffb458b
  • binutils-s390x-linux-gnu_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:df93aa0da517af92962a96eeb0b7c5e2dbc2d62d
  • binutils-sh4-linux-gnu_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:7222792bc2ccf284ea1bdede6701894b8fa9f234
  • binutils-source_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_all.deb
    sha:87d19c7efc0807c77af4341a2ff8b5c490252a6a
  • binutils-sparc64-linux-gnu_2.26.1-1ubuntu1~16.04.10+tuxcare.els10_amd64.deb
    sha:ee232f417f23abecf59e1ed4cf3ba56c8daa6bd8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.