binutils-2.30-125.el8_10

エラータID: AXSA:2024-9023:03

Release date: 
Monday, November 18, 2024 - 21:05
Subject: 
binutils-2.30-125.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Low
Description: 

The binutils packages provide a collection of binary utilities for the manipulation of object code in various object file formats. It includes the ar, as, gprof, ld, nm, objcopy, objdump, ranlib, readelf, size, strings, strip, and addr2line utilities.

Security Fix(es):

* binutils: heap-based buffer overflow in finish_stab in stabs.c (CVE-2018-12699)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2018-12699
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. binutils-2.30-125.el8_10.src.rpm
    MD5: 247c87c41253f8cf3b73889404e4690a
    SHA-256: 0fc9a1e208da965b04243defc428282c8fc149d742bc37885918e47af476cdf4
    Size: 20.10 MB

Asianux Server 8 for x86_64
  1. binutils-2.30-125.el8_10.x86_64.rpm
    MD5: 6f6aa017c51af636375479bbc35e438f
    SHA-256: 9f80257f00d86c36bb9b818653d17f29c70a97a9ed17789f12e1f6a4c6a7ade7
    Size: 5.77 MB
  2. binutils-devel-2.30-125.el8_10.i686.rpm
    MD5: 8e47ef07887e3c4d2a205d481daf63dd
    SHA-256: 0967a9fa44041bf41f3df459c9f2db5df3211ff435550bf6378746c3af29e990
    Size: 3.45 MB
  3. binutils-devel-2.30-125.el8_10.x86_64.rpm
    MD5: 581409d4e542269634d81f3354e71d7f
    SHA-256: 0aa699260745dfe03c963cf542bb48b1f5726a899a63ccdc8eb9b57dd1b47612
    Size: 3.60 MB