Fedora 29: binutils Security Update
Summary
Binutils is a collection of binary utilities, including ar (for
creating, modifying and extracting from archives), as (a family of GNU
assemblers), gprof (for displaying call graph profile data), ld (the
GNU linker), nm (for listing symbols from object files), objcopy (for
copying and translating object files), objdump (for displaying
information from object files), ranlib (for generating an index for
the contents of an archive), readelf (for displaying detailed
information about binary files), size (for listing the section sizes
of an object or archive file), strings (for listing printable strings
from files), strip (for discarding symbols), and addr2line (for
converting addresses to file and line).
Bug fixes for binutils including one that is preventing Yocot/oe-core from
building properly
* Wed Jan 30 2019 Nick Clifton
- Fix the assembler's check that the output file is not also one of the input files. (#1660279)
* Thu Jan 3 2019 Nick Clifton
- Fix a memory leak reading minisymbols. (#1661535)
* Wed Nov 28 2018 Nick Clifton
- Stop gold from warning about discard version information unless explicitly requested. (#1654153)
* Thu Nov 15 2018 Nick Clifton
- Remove debugging fprintf statement accidentally left in patch. (#1645828)
[ 1 ] Bug #1546608 - ld does not merge .gnu.build.attributes
https://bugzilla.redhat.com/show_bug.cgi?id=1546608
[ 2 ] Bug #1515934 - Mir build fails on ppc64 when LTO is enabled
https://bugzilla.redhat.com/show_bug.cgi?id=1515934
[ 3 ] Bug #1660279 - as from binutils 2.31.1 may fail at some certain condition
https://bugzilla.redhat.com/show_bug.cgi?id=1660279
[ 4 ] Bug #1646536 - CVE-2018-18700 binutils: Recursive Stack Overflow within function d_name, d_encoding, and d_local_name in cp-demangle.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1646536
[ 5 ] Bug #1553086 - gdb: warning: Loadable section ".note.gnu.property" outside of ELF segments
https://bugzilla.redhat.com/show_bug.cgi?id=1553086
[ 6 ] Bug #1483604 - CVE-2017-12448 CVE-2017-12449 CVE-2017-12450 CVE-2017-12451 CVE-2017-12452 CVE-2017-12453 CVE-2017-12454 CVE-2017-12455 CVE-2017-12456 CVE-2017-12457 CVE-2017-12458 CVE-2017-12459 CVE-2017-13710 CVE-2017-13716 binutils: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1483604
[ 7 ] Bug #1639969 - After recent update, gold linker crashes while building chromium with fedora build flags
https://bugzilla.redhat.com/show_bug.cgi?id=1639969
[ 8 ] Bug #1626622 - readelf --unwind not supported
https://bugzilla.redhat.com/show_bug.cgi?id=1626622
su -c 'dnf upgrade --advisory FEDORA-2019-ba3cbcfd20' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
FEDORA-2019-ba3cbcfd20 2019-02-02 03:34:29.460572 Product : Fedora 29 Version : 2.31.1 Release : 17.fc29 URL : https://sourceware.org/binutils/ Summary : A GNU collection of binary utilities Description : Binutils is a collection of binary utilities, including ar (for creating, modifying and extracting from archives), as (a family of GNU assemblers), gprof (for displaying call graph profile data), ld (the GNU linker), nm (for listing symbols from object files), objcopy (for copying and translating object files), objdump (for displaying information from object files), ranlib (for generating an index for the contents of an archive), readelf (for displaying detailed information about binary files), size (for listing the section sizes of an object or archive file), strings (for listing printable strings from files), strip (for discarding symbols), and addr2line (for converting addresses to file and line). Bug fixes for binutils including one that is preventing Yocot/oe-core from building properly * Wed Jan 30 2019 Nick Clifton - 2.31.1-17 - Fix the assembler's check that the output file is not also one of the input files. (#1660279) * Thu Jan 3 2019 Nick Clifton - 2.31.1-16 - Fix a memory leak reading minisymbols. (#1661535) * Wed Nov 28 2018 Nick Clifton - 2.31.1-15 - Stop gold from warning about discard version information unless explicitly requested. (#1654153) * Thu Nov 15 2018 Nick Clifton - 2.31.1-14 - Remove debugging fprintf statement accidentally left in patch. (#1645828) [ 1 ] Bug #1546608 - ld does not merge .gnu.build.attributes https://bugzilla.redhat.com/show_bug.cgi?id=1546608 [ 2 ] Bug #1515934 - Mir build fails on ppc64 when LTO is enabled https://bugzilla.redhat.com/show_bug.cgi?id=1515934 [ 3 ] Bug #1660279 - as from binutils 2.31.1 may fail at some certain condition https://bugzilla.redhat.com/show_bug.cgi?id=1660279 [ 4 ] Bug #1646536 - CVE-2018-18700 binutils: Recursive Stack Overflow within function d_name, d_encoding, and d_local_name in cp-demangle.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1646536 [ 5 ] Bug #1553086 - gdb: warning: Loadable section ".note.gnu.property" outside of ELF segments https://bugzilla.redhat.com/show_bug.cgi?id=1553086 [ 6 ] Bug #1483604 - CVE-2017-12448 CVE-2017-12449 CVE-2017-12450 CVE-2017-12451 CVE-2017-12452 CVE-2017-12453 CVE-2017-12454 CVE-2017-12455 CVE-2017-12456 CVE-2017-12457 CVE-2017-12458 CVE-2017-12459 CVE-2017-13710 CVE-2017-13716 binutils: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1483604 [ 7 ] Bug #1639969 - After recent update, gold linker crashes while building chromium with fedora build flags https://bugzilla.redhat.com/show_bug.cgi?id=1639969 [ 8 ] Bug #1626622 - readelf --unwind not supported https://bugzilla.redhat.com/show_bug.cgi?id=1626622 su -c 'dnf upgrade --advisory FEDORA-2019-ba3cbcfd20' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Change Log
References