ALAS-2023-334


Amazon Linux 2023 Security Advisory: ALAS-2023-334
Advisory Release Date: 2023-08-31 21:46 Pacific
Advisory Updated Date: 2023-09-07 21:18 Pacific
Severity: Medium

Issue Overview:

Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c. (CVE-2022-45703)

An issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a denial of service or other unspecified impacts. (CVE-2022-47673)

An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function bfd_mach_o_get_synthetic_symtab in match-o.c. (CVE-2022-47695)

An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols. (CVE-2022-47696)

GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_separate_debug_files at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. (CVE-2022-48063)

GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. (CVE-2022-48064)

GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c. (CVE-2022-48065)


Affected Packages:

binutils


Issue Correction:
Run dnf update binutils --releasever 2023.1.20230906 to update your system.

New Packages:
aarch64:
    binutils-gprofng-debuginfo-2.39-6.amzn2023.0.9.aarch64
    binutils-devel-2.39-6.amzn2023.0.9.aarch64
    binutils-debuginfo-2.39-6.amzn2023.0.9.aarch64
    binutils-gprofng-2.39-6.amzn2023.0.9.aarch64
    binutils-debugsource-2.39-6.amzn2023.0.9.aarch64
    binutils-2.39-6.amzn2023.0.9.aarch64

src:
    binutils-2.39-6.amzn2023.0.9.src

x86_64:
    binutils-devel-2.39-6.amzn2023.0.9.x86_64
    binutils-gprofng-debuginfo-2.39-6.amzn2023.0.9.x86_64
    binutils-gprofng-2.39-6.amzn2023.0.9.x86_64
    binutils-debuginfo-2.39-6.amzn2023.0.9.x86_64
    binutils-2.39-6.amzn2023.0.9.x86_64
    binutils-debugsource-2.39-6.amzn2023.0.9.x86_64