Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.2.2019.1836
Categoría:Huawei EulerOS Local Security Checks
Título:Huawei EulerOS: Security Advisory for binutils (EulerOS-SA-2019-1836)
Resumen:The remote host is missing an update for the Huawei EulerOS 'binutils' package(s) announced via the EulerOS-SA-2019-1836 advisory.
Descripción:Summary:
The remote host is missing an update for the Huawei EulerOS 'binutils' package(s) announced via the EulerOS-SA-2019-1836 advisory.

Vulnerability Insight:
The _bfd_elf_parse_attributes function in elf-attrs.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (_bfd_elf_attr_strdup heap-based buffer over-read and application crash) via a crafted ELF file.(CVE-2017-14130)

The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during 'objdump -D' execution.(CVE-2017-9756)

The process_otr function in bfd/versados.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, does not validate a certain offset, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during 'objdump -D' execution.(CVE-2017-9754)

The versados_mkobject function in bfd/versados.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, does not initialize a certain data structure, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during 'objdump -D' execution.(CVE-2017-9753)

bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file in the _bfd_vms_get_value and _bfd_vms_slurp_etir functions during 'objdump -D' execution.(CVE-2017-9752)

The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during 'objdump -D' execution.(CVE-2017-9749)

The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during 'objdump -D' execution. NOTE: this may be related to a compiler bug.(CVE-2017-9748)

The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow ... [Please see the references for more information on the vulnerabilities]

Affected Software/OS:
'binutils' package(s) on Huawei EulerOS V2.0SP2.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-7302
BugTraq ID: 97216
http://www.securityfocus.com/bid/97216
Common Vulnerability Exposure (CVE) ID: CVE-2017-7303
BugTraq ID: 97213
http://www.securityfocus.com/bid/97213
Common Vulnerability Exposure (CVE) ID: CVE-2017-8396
https://security.gentoo.org/glsa/201709-02
Common Vulnerability Exposure (CVE) ID: CVE-2017-8397
Common Vulnerability Exposure (CVE) ID: CVE-2017-8398
Common Vulnerability Exposure (CVE) ID: CVE-2017-9040
BugTraq ID: 98579
http://www.securityfocus.com/bid/98579
https://blogs.gentoo.org/ago/2017/05/12/binutils-multiple-crashes/
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7296a62a2a237f6b1ad8db8c38b090e9f592c8cf
Common Vulnerability Exposure (CVE) ID: CVE-2017-9042
Common Vulnerability Exposure (CVE) ID: CVE-2017-9742
BugTraq ID: 99105
http://www.securityfocus.com/bid/99105
https://www.exploit-db.com/exploits/42203/
Common Vulnerability Exposure (CVE) ID: CVE-2017-9744
BugTraq ID: 99108
http://www.securityfocus.com/bid/99108
Common Vulnerability Exposure (CVE) ID: CVE-2017-9746
BugTraq ID: 99117
http://www.securityfocus.com/bid/99117
https://www.exploit-db.com/exploits/42199/
https://security.gentoo.org/glsa/201801-01
Common Vulnerability Exposure (CVE) ID: CVE-2017-9747
BugTraq ID: 99114
http://www.securityfocus.com/bid/99114
https://www.exploit-db.com/exploits/42200/
Common Vulnerability Exposure (CVE) ID: CVE-2017-9748
BugTraq ID: 99110
http://www.securityfocus.com/bid/99110
https://www.exploit-db.com/exploits/42202/
Common Vulnerability Exposure (CVE) ID: CVE-2017-9749
BugTraq ID: 99113
http://www.securityfocus.com/bid/99113
https://www.exploit-db.com/exploits/42201/
Common Vulnerability Exposure (CVE) ID: CVE-2017-9752
BugTraq ID: 99122
http://www.securityfocus.com/bid/99122
Common Vulnerability Exposure (CVE) ID: CVE-2017-9753
BugTraq ID: 99116
http://www.securityfocus.com/bid/99116
Common Vulnerability Exposure (CVE) ID: CVE-2017-9754
BugTraq ID: 99125
http://www.securityfocus.com/bid/99125
Common Vulnerability Exposure (CVE) ID: CVE-2017-9756
BugTraq ID: 99103
http://www.securityfocus.com/bid/99103
https://www.exploit-db.com/exploits/42204/
Common Vulnerability Exposure (CVE) ID: CVE-2019-9075
https://security.gentoo.org/glsa/202107-24
https://sourceware.org/bugzilla/show_bug.cgi?id=24236
SuSE Security Announcement: openSUSE-SU-2020:1790 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html
SuSE Security Announcement: openSUSE-SU-2020:1804 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html
https://usn.ubuntu.com/4336-1/
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.