Bug 36982 - binutils: Multiple issues (ES 3.2)
binutils: Multiple issues (ES 3.2)
Status: CLOSED WONTFIX
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 3.2
Other Linux
: P3 normal (vote)
: UCS 3.2-x-errata
Assigned To: UCS maintainers
:
Depends on:
Blocks: 36983
  Show dependency treegraph
 
Reported: 2014-11-25 07:06 CET by Moritz Muehlenhoff
Modified: 2019-04-11 19:23 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Security
Max CVSS v3 score: 6.8 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
requate: Patch_Available+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Moritz Muehlenhoff univentionstaff 2014-11-25 07:06:58 CET
Multiple security issues have been found in binutils and the included bfd library,
which is e.g. used by strings(1), nm, objdump or gdb:

Invalid read in libbfd (CVE-2014-8484)  
Buffer overflow in libbfd (CVE-2014-8485)
Out of bounds write when parsing PE executables (CVE-2014-8501) 
Heap overflow in objdump (CVE-2014-8502)
Buffer overflow in objdump when parsing ihex files (CVE-2014-8503)
Buffer overflow in parsing S-Records (CVE-2014-8504)
Directory traversal in ar and objcopy (CVE-2014-8737)
Out of bounds write in ar (CVE-2014-8738)
Comment 1 Arvid Requate univentionstaff 2015-08-17 11:22:02 CEST
Fixed in 2.20.1-16+deb6u1
Comment 2 Arvid Requate univentionstaff 2017-02-16 16:51:01 CET
2.20.1-16+deb6u2 also fixes:

* Fix integer overflow in objalloc_alloc (CVE-2012-3509)


Additionally, check the wheezy patches (e.g. Bug 41814) for backport.


Note: squeeze-lts packages have been archived:

printf "deb-src\thttp://archive.debian.org/debian\tsqueeze-lts\tmain" \
       >> /etc/apt/sources.list
apt-get --qq update
apt-get source binutils
Comment 3 Stefan Gohmann univentionstaff 2017-06-16 20:36:32 CEST
This issue has been filed against UCS 3. UCS 3 is out of the normal maintenance and many UCS components have vastly changed in UCS 4.

If this issue is still valid, please change the version to a newer UCS version otherwise this issue will be automatically closed in the next weeks.