ubuntu/+source/elfutils:applied/ubuntu/trusty-updates

Last commit made on 2018-06-05
Get this branch:
git clone -b applied/ubuntu/trusty-updates https://git.launchpad.net/ubuntu/+source/elfutils
Members of Ubuntu Server Dev import team can upload to this branch. Log in for directions.

Branch merges

Branch information

Name:
applied/ubuntu/trusty-updates
Repository:
lp:ubuntu/+source/elfutils

Recent commits

9abd32a... by Tyler Hicks on 2017-05-17

Import patches-applied version 0.158-0ubuntu5.3 to applied/ubuntu/trusty-security

Imported using git-ubuntu import.

Changelog parent: e36b4a405bb6649c0d1cb1db5f5626e44aff4775
Unapplied parent: 36814baafadd7e9328d1c54c1e802ec7f7d083b3

New changelog entries:
  * SECURITY UPDATE: Denial of service via invalid memory read when handling
    crafted ELF files
    - debian/patches/CVE-2016-10254.patch: Always set ELF maxsize when reading
      an ELF file for sanity checks. Based on upstream patch.
    - CVE-2016-10254
  * SECURITY UPDATE: Denial of service via memory consumption when handling
    crafted ELF files
    - debian/patches/CVE-2016-10255.patch: Sanity check offset and size before
      trying to malloc and read data. Based on upstream patch.
    - CVE-2016-10255
  * SECURITY UPDATE: Denial of service via invalid memory read when handling
    crafted ELF files
    - debian/patches/CVE-2017-7607-1.patch: Sanity check hash section contents
      before processing. Based on upstream patch.
    - debian/patches/CVE-2017-7607-2.patch: Fix off by one sanity check in
      handle_gnu_hash. Based on upstream patch.
    - CVE-2017-7607
  * SECURITY UPDATE: Denial of service via invalid memory read when handling
    crafted ELF files
    - debian/patches/CVE-2017-7608.patch: Use the empty string for note names
      with zero size. Based on upstream patch.
    - CVE-2017-7608
  * SECURITY UPDATE: Denial of service via invalid memory read when handling
    crafted ELF files
    - debian/patches/CVE-2017-7610.patch: Don't check section group without
      flags word. Based on upstream patch.
    - CVE-2017-7610
  * SECURITY UPDATE: Denial of service via invalid memory read when handling
    crafted ELF files
    - debian/patches/CVE-2017-7611.patch: Check symbol table data is big
      enough before checking. Based on upstream patch.
    - CVE-2017-7611
  * SECURITY UPDATE: Denial of service via invalid memory read when handling
    crafted ELF files
    - debian/patches/CVE-2017-7612.patch: Don't trust sh_entsize when checking
      hash sections. Based on upstream patch.
    - CVE-2017-7612
  * SECURITY UPDATE: Denial of service via memory consumption when handling
    crafted ELF files
    - debian/patches/CVE-2017-7613.patch: Sanity check the number of phdrs and
      shdrs available. Based on upstream patch.
    - CVE-2017-7613

36814ba... by Tyler Hicks on 2017-05-17

[PATCH] elflint: Sanity check the number of phdrs and shdrs

Gbp-Pq: CVE-2017-7613.patch.

cefc3b6... by Tyler Hicks on 2017-05-17

[PATCH] elflint: Don't trust sh_entsize when checking hash sections.

Gbp-Pq: CVE-2017-7612.patch.

e1fee22... by Tyler Hicks on 2017-05-17

[PATCH] elflint: Check symbol table data is big enough before

Gbp-Pq: CVE-2017-7611.patch.

0268fe2... by Tyler Hicks on 2017-05-17

[PATCH] elflint: Don't check section group without flags word.

Gbp-Pq: CVE-2017-7610.patch.

f64598b... by Tyler Hicks on 2017-05-17

[PATCH] Use the empty string for note names with zero size (without

Gbp-Pq: CVE-2017-7608.patch.

0d77a2e... by Tyler Hicks on 2017-05-17

[PATCH] readelf: Fix off by one sanity check in handle_gnu_hash.

Gbp-Pq: CVE-2017-7607-2.patch.

441873a... by Tyler Hicks on 2017-05-17

[PATCH] readelf: Sanity check hash section contents before

Gbp-Pq: CVE-2017-7607-1.patch.

ec02245... by Tyler Hicks on 2017-05-17

[PATCH] libelf: Sanity check offset and size before trying to malloc

Gbp-Pq: CVE-2016-10255.patch.

63e5615... by Tyler Hicks on 2017-05-17

[PATCH] libelf: Always set ELF maxsize when reading an ELF file for

Gbp-Pq: CVE-2016-10254.patch.