Scientific Linux Security Update : binutils on SL7.x x86_64 (20181030)

high Nessus Plugin ID 119179
New! Plugin Severity Now Using CVSS v3

The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Synopsis

The remote Scientific Linux host is missing one or more security updates.

Description

Security Fix(es) :

- binutils: Improper bounds check in coffgen.c:coff_pointerize_aux() allows for denial of service when parsing a crafted COFF file (CVE-2018-7208)

- binutils: integer overflow via an ELF file with corrupt dwarf1 debug information in libbfd library (CVE-2018-7568)

- binutils: integer underflow or overflow via an ELF file with a corrupt DWARF FORM block in libbfd library (CVE-2018-7569)

- binutils: NULL pointer dereference in swap_std_reloc_in function in aoutx.h resulting in crash (CVE-2018-7642)

- binutils: Integer overflow in the display_debug_ranges function resulting in crash (CVE-2018-7643)

- binutils: Crash in elf.c:bfd_section_from_shdr() with crafted executable (CVE-2018-8945)

- binutils: Heap-base buffer over-read in dwarf.c:process_cu_tu_index() allows for denial of service via crafted file (CVE-2018-10372)

- binutils: NULL pointer dereference in dwarf2.c:concat_filename() allows for denial of service via crafted file (CVE-2018-10373)

- binutils: out of bounds memory write in peXXigen.c files (CVE-2018-10534)

- binutils: NULL pointer dereference in elf.c (CVE-2018-10535)

- binutils: Uncontrolled Resource Consumption in execution of nm (CVE-2018-13033)

Solution

Update the affected binutils, binutils-debuginfo and / or binutils-devel packages.

See Also

http://www.nessus.org/u?4528db8f

Plugin Details

Severity: High

ID: 119179

File Name: sl_20181030_binutils_on_SL7_x.nasl

Version: 1.5

Type: local

Agent: unix

Published: 11/27/2018

Updated: 7/1/2020

Dependencies: ssh_get_info.nasl

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: E:U/RL:OF/RC:C

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:fermilab:scientific_linux:binutils, p-cpe:/a:fermilab:scientific_linux:binutils-debuginfo, p-cpe:/a:fermilab:scientific_linux:binutils-devel, x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 10/30/2018

Vulnerability Publication Date: 2/18/2018

Reference Information

CVE: CVE-2018-10372, CVE-2018-10373, CVE-2018-10534, CVE-2018-10535, CVE-2018-13033, CVE-2018-7208, CVE-2018-7568, CVE-2018-7569, CVE-2018-7642, CVE-2018-7643, CVE-2018-8945