SUSE: 2019:2650-1 moderate: binutils
Summary
This update for binutils fixes the following issues: binutils was updated to current 2.32 branch @7b468db3 [jsc#ECO-368]: Includes the following security fixes: - CVE-2018-17358: Fixed invalid memory access in _bfd_stab_section_find_nearest_line in syms.c (bsc#1109412) - CVE-2018-17359: Fixed invalid memory access exists in bfd_zalloc in opncls.c (bsc#1109413) - CVE-2018-17360: Fixed heap-based buffer over-read in bfd_getl32 in libbfd.c (bsc#1109414) - CVE-2018-17985: Fixed a stack consumption problem caused by the cplus_demangle_type (bsc#1116827) - CVE-2018-18309: Fixed an invalid memory address dereference was discovered in read_reloc in reloc.c (bsc#1111996) - CVE-2018-18483: Fixed get_count function provided by libiberty that allowed attackers to cause a denial of service or other unspecified impact (bsc#1112535) - CVE-2018-18484: Fixed stack exhaustion in the C++ demangling functions provided by libiber...
Read the Full AdvisoryReferences
#1109412 #1109413 #1109414 #1111996 #1112534
#1112535 #1113247 #1113252 #1113255 #1116827
#1118830 #1118831 #1120640 #1121034 #1121035
#1121056 #1133131 #1133232 #1141913 #1142772
Cross- CVE-2018-1000876 CVE-2018-17358 CVE-2018-17359
CVE-2018-17360 CVE-2018-17985 CVE-2018-18309
CVE-2018-18483 CVE-2018-18484 CVE-2018-18605
CVE-2018-18606 CVE-2018-18607 CVE-2018-19931
CVE-2018-19932 CVE-2018-20623 CVE-2018-20651
CVE-2018-20671 CVE-2019-1010180
Affected Products:
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 7
SUSE Linux Enterprise Software Development Kit 12-SP5
SUSE Linux Enterprise Software Development Kit 12-SP4
SUSE Linux Enterprise Server for SAP 12-SP3
...
Read the Full Advisory