Files
buildroot/package
Fabrice Fontaine 725531fc32 package/elfutils: security bump to version 0.176
Fixes CVE-2018-18310: An invalid memory address dereference was
discovered in dwfl_segment_report_module.c in libdwfl in elfutils
through v0.174. The vulnerability allows attackers to cause a denial of
service (application crash) with a crafted ELF file, as demonstrated by
consider_notes.

Fixes CVE-2018-18520: An Invalid Memory Address Dereference exists in
the function elf_end in libelf in elfutils through v0.174. Although
eu-size is intended to support ar files inside ar files,
handle_ar in size.c closes the outer ar file before handling all inner
entries. The vulnerability allows attackers to cause a denial of service
(application crash) with a crafted ELF file.

Fixes CVE-2018-18521: Divide-by-zero vulnerabilities in the function
arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers
to cause a denial of service (application crash) with a crafted ELF
file, as demonstrated by eu-ranlib, because a zero sh_entsize is
mishandled.

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2019-08-03 14:27:59 +02:00
..
2019-08-01 11:47:04 +02:00
2019-08-01 12:52:29 +02:00
2019-08-01 10:54:37 +02:00
2019-08-02 22:51:54 +02:00
2019-08-02 22:49:23 +02:00
2019-08-01 11:03:04 +02:00
2019-08-01 10:44:38 +02:00
2019-08-01 09:33:40 +02:00
2019-08-01 18:43:19 +02:00
2019-08-01 09:38:53 +02:00
2019-08-01 09:39:50 +02:00
2019-07-28 09:30:36 +02:00
2019-08-01 10:57:26 +02:00
2019-08-02 22:25:55 +02:00
2019-08-02 17:10:50 +02:00
2019-08-01 00:44:43 +02:00
2019-08-01 18:31:51 +02:00
2019-08-02 22:46:14 +02:00
2019-08-01 21:01:17 +02:00
2019-07-30 17:54:20 +02:00
2019-08-01 00:38:14 +02:00
2019-08-03 00:32:27 +02:00
2019-08-01 09:35:19 +02:00
2019-08-03 11:06:44 +02:00
2019-08-01 10:40:26 +02:00
2019-08-01 10:40:45 +02:00
2019-08-03 00:26:48 +02:00
2019-08-03 11:06:44 +02:00
2019-08-01 12:52:29 +02:00