Amazon Linux 2023 Security Advisory: ALAS-2023-334
Advisory Release Date: 2023-08-31 21:46 Pacific
Advisory Updated Date: 2023-09-07 21:18 Pacific
FAQs regarding Amazon Linux ALAS/CVE Severity
Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c. (CVE-2022-45703)
An issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a denial of service or other unspecified impacts. (CVE-2022-47673)
An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function bfd_mach_o_get_synthetic_symtab in match-o.c. (CVE-2022-47695)
An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols. (CVE-2022-47696)
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_separate_debug_files at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. (CVE-2022-48063)
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. (CVE-2022-48064)
GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c. (CVE-2022-48065)
Affected Packages:
binutils
Issue Correction:
Run dnf update binutils --releasever 2023.1.20230906 to update your system.
aarch64:
binutils-gprofng-debuginfo-2.39-6.amzn2023.0.9.aarch64
binutils-devel-2.39-6.amzn2023.0.9.aarch64
binutils-debuginfo-2.39-6.amzn2023.0.9.aarch64
binutils-gprofng-2.39-6.amzn2023.0.9.aarch64
binutils-debugsource-2.39-6.amzn2023.0.9.aarch64
binutils-2.39-6.amzn2023.0.9.aarch64
src:
binutils-2.39-6.amzn2023.0.9.src
x86_64:
binutils-devel-2.39-6.amzn2023.0.9.x86_64
binutils-gprofng-debuginfo-2.39-6.amzn2023.0.9.x86_64
binutils-gprofng-2.39-6.amzn2023.0.9.x86_64
binutils-debuginfo-2.39-6.amzn2023.0.9.x86_64
binutils-2.39-6.amzn2023.0.9.x86_64
binutils-debugsource-2.39-6.amzn2023.0.9.x86_64