Debian-LTS alert DLA-669-1 (dwarfutils)
| From: | Daniel Stender <stender@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 669-1] dwarfutils security update | |
| Date: | Wed, 19 Oct 2016 16:57:04 +0200 | |
| Message-ID: | <85e2dfd6-2af9-c20a-7140-ebaefe9eecaa@debian.org> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : dwarfutils Version : 20120410-2+deb7u2 CVE ID : CVE-2015-8538 CVE-2015-8750 CVE-2016-2050 CVE-2016-2091 CVE-2016-5034 CVE-2016-5036 CVE-2016-5038 CVE-2016-5039 CVE-2016-5042 Several vulnerabilities were discovered in dwarfutils, a tool and library for reading/consuming and writing/producing DWARF debugging information. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2015-8538 A specially crafted ELF file can cause a segmentation fault. CVE-2015-8750 A specially crafted ELF file can cause a NULL pointer dereference. CVE-2016-2050 Out-of-bounds write CVE-2016-2091 Out-of-bounds read CVE-2016-5034 Out-of-bounds write CVE-2016-5036 Out-of-bounds read CVE-2016-5038 Out-of-bounds read CVE-2016-5039 Out-of-bounds read CVE-2016-5042 A specially crafted DWARF section can cause an infinite loop, reading from increasing memory addresses until the application crashes. For Debian 7 "Wheezy", these problems have been fixed in version 20120410-2+deb7u2. We recommend that you upgrade your dwarfutils packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIcBAEBCgAGBQJYB4m9AAoJEBXgmvTfUYLI8RcP/2kw/E8DkdcwCBmctbfrp5wS tIIbY+M1YSC2B4i26l9DK3B/DER0GueYK0R1M9TXclDKyhz5bDa6qAtkXG6ewkta BJxyC+LZoZJd3weyIN6W1/1ovnyWJpfheoUfETIPPwIiYQRV3wJEXe0YNfvzifCi uiJohen2b0kgcQOLXNi0lymoYGvOs9jodrKu+QhwbaDq/fGONd1/hIHU9dAGwqGH RuB6GZksMpEKtmnOn4PS0d1QWkYJiqSHeYGbqOdpKQ3wADXQdBVAtxz86aKpRqyd WyHWf4UqCTqgLeYIkhQ6K7pu7QFLqVLjhduQZEtaw00EvuxP9F18EE6opA5dgVVz ZQoOhlal+MJMKZjDDTr0vag30eevu2+WHiv//2dp2OqU5NpMLbnVCCcCF2OOLkc2 s+g+LnH98yY4cAy0IhyaUgjGrs0Kwx7PmUDDxk3eeN3XLtIg9WKv6ZhKEe6R92V7 gVeDUkaLYeyTEo/+lSMO/LejLEdNI8ywXyn0F2cJJ4y3bnuQmByoPfeQuEJDf1La PA3Fy8vcb4NT+Fdo1dEQB+2wMfqAXaHXlhz3JVfHk+g492sBeCTkO7vpKZUKkowK aP/2g09Xn3fGxtAoADIIl+M93428U8ei9NLcc4Ns7/ZixnChPSY4i5zFAu6sz2Mn 5OocZnwgHJM1dVhSIf1e =dvnA -----END PGP SIGNATURE-----
