{"id":"CLSA-2023-1696877581","summary":"binutils: Fix of 9 CVEs","details":"- CVE-2017-16831: Fix excessive memory allocation attempts and possible integer\n  overflows when attempting to read a COFF binary with a corrupt symbol count\n- CVE-2020-19726: Fix parsing a corrupt PE format file\n- CVE-2021-45078: Fix out-of-bounds write in stab_xcoff_builtin_type\n- CVE-2021-46174: Fix buffer overflow in read_section_stabs_debugging_info\n- CVE-2022-44840: Fix possible heap buffer overflow in find_section_in_set() in readelf.c\n- CVE-2022-45703: Combine sanity checks, calculate element counts, not word\n  counts, fix typo\n- CVE-2022-47695: Test symbol flags to exclude section and synthetic symbols\n  before attempting to check flavour\n- CVE-2022-47696: Fix uninitialised field `the_bfd` of `asymbol`\n- CVE-2022-47673: Fix lack of bounds checking in vms-alpha.c","modified":"2026-05-27T11:35:41.870709662Z","published":"2023-10-09T18:53:05Z","upstream":["CVE-2017-16831","CVE-2020-19726","CVE-2021-45078","CVE-2021-46174","CVE-2022-44840","CVE-2022-45703","CVE-2022-47673","CVE-2022-47695","CVE-2022-47696"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/centos7-els/CLSA-2023-1696877581.html"}],"affected":[{"package":{"name":"binutils","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/binutils?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27-44.base.el7_9.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2023-1696877581.json"}},{"package":{"name":"binutils-devel","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/binutils-devel?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27-44.base.el7_9.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2023-1696877581.json"}}],"schema_version":"1.7.5"}