MGASA-2024-0246

Source
https://advisories.mageia.org/MGASA-2024-0246.html
Import Source
https://advisories.mageia.org/MGASA-2024-0246.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2024-0246
Upstream
Published
2024-07-01T17:53:27Z
Modified
2026-04-16T04:44:03Z
Summary
Updated gdb packages fix security vulnerabilities
Details

An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599. (CVE-2022-4285) A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability. (CVE-2023-1972) GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a stack overflow via the function ada_decode at /gdb/ada-lang.c. (CVE-2023-39128) GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function add_pe_exported_sym() at /gdb/coff-pe-read.c. (CVE-2023-39129) GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function pe_as16() at /gdb/coff-pe-read.c. (CVE-2023-39130)

References
Credits

Affected packages

Mageia:9 / gdb

Package

Name
gdb
Purl
pkg:rpm/mageia/gdb?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
12.1-7.1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2024-0246.json"