openSUSE-SU-2019:1590-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:1590-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2019:1590-1
Upstream
CVE (15)
Related
Published
2019-06-19T20:18:43Z
Modified
2026-03-11T07:32:08Z
Summary
Security update for elfutils
Details

This update for elfutils fixes the following issues:

Security issues fixed:

  • CVE-2017-7607: Fixed a heap-based buffer overflow in handle_gnu_hash (bsc#1033084)
  • CVE-2017-7608: Fixed a heap-based buffer overflow in ebl_object_note_type_name() (bsc#1033085)
  • CVE-2017-7609: Fixed a memory allocation failure in __libelf_decompress (bsc#1033086)
  • CVE-2017-7610: Fixed a heap-based buffer overflow in check_group (bsc#1033087)
  • CVE-2017-7611: Fixed a denial of service via a crafted ELF file (bsc#1033088)
  • CVE-2017-7612: Fixed a denial of service in check_sysv_hash() via a crafted ELF file (bsc#1033089)
  • CVE-2017-7613: Fixed denial of service caused by the missing validation of the number of sections and the number of segments in a crafted ELF file (bsc#1033090)
  • CVE-2018-16062: Fixed a heap-buffer overflow in /elfutils/libdw/dwarf_getaranges.c:156 (bsc#1106390)
  • CVE-2018-16402: Fixed a denial of service/double free on an attempt to decompress the same section twice (bsc#1107066)
  • CVE-2018-16403: Fixed a heap buffer overflow in readelf (bsc#1107067)
  • CVE-2018-18310: Fixed an invalid address read problem in dwfl_segment_report_module.c (bsc#1111973)
  • CVE-2018-18520: Fixed bad handling of ar files inside are files (bsc#1112726)
  • CVE-2018-18521: Fixed a denial of service vulnerabilities in the function arlib_add_symbols() used by eu-ranlib (bsc#1112723)
  • CVE-2019-7150: dwfl_segment_report_module doesn't check whether the dyn data read from core file is truncated (bsc#1123685)
  • CVE-2019-7665: NT_PLATFORM core file note should be a zero terminated string (bsc#1125007)

This update was imported from the SUSE:SLE-15:Update update project.

References

Affected packages

openSUSE:Leap 15.0 / elfutils

Package

Name
elfutils
Purl
pkg:rpm/opensuse/elfutils&distro=openSUSE%20Leap%2015.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.168-lp151.4.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "elfutils":  "0.168-lp151.4.3.1",
            "elfutils-lang":  "0.168-lp151.4.3.1",
            "libasm-devel":  "0.168-lp151.4.3.1",
            "libasm1":  "0.168-lp151.4.3.1",
            "libasm1-32bit":  "0.168-lp151.4.3.1",
            "libdw-devel":  "0.168-lp151.4.3.1",
            "libdw1":  "0.168-lp151.4.3.1",
            "libdw1-32bit":  "0.168-lp151.4.3.1",
            "libebl-devel":  "0.168-lp151.4.3.1",
            "libebl-plugins":  "0.168-lp151.4.3.1",
            "libebl-plugins-32bit":  "0.168-lp151.4.3.1",
            "libelf-devel":  "0.168-lp151.4.3.1",
            "libelf-devel-32bit":  "0.168-lp151.4.3.1",
            "libelf1":  "0.168-lp151.4.3.1",
            "libelf1-32bit":  "0.168-lp151.4.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:1590-1.json"

openSUSE:Leap 15.1 / elfutils

Package

Name
elfutils
Purl
pkg:rpm/opensuse/elfutils&distro=openSUSE%20Leap%2015.1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.168-lp151.4.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "elfutils":  "0.168-lp151.4.3.1",
            "elfutils-lang":  "0.168-lp151.4.3.1",
            "libasm-devel":  "0.168-lp151.4.3.1",
            "libasm1":  "0.168-lp151.4.3.1",
            "libasm1-32bit":  "0.168-lp151.4.3.1",
            "libdw-devel":  "0.168-lp151.4.3.1",
            "libdw1":  "0.168-lp151.4.3.1",
            "libdw1-32bit":  "0.168-lp151.4.3.1",
            "libebl-devel":  "0.168-lp151.4.3.1",
            "libebl-plugins":  "0.168-lp151.4.3.1",
            "libebl-plugins-32bit":  "0.168-lp151.4.3.1",
            "libelf-devel":  "0.168-lp151.4.3.1",
            "libelf-devel-32bit":  "0.168-lp151.4.3.1",
            "libelf1":  "0.168-lp151.4.3.1",
            "libelf1-32bit":  "0.168-lp151.4.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:1590-1.json"