
USN-3368-1: libiberty vulnerabilities
USN-3368-1: libiberty vulnerabilities Ubuntu Security Notice USN-3368-1 26th July, 2017 libiberty vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in libiberty. Software description libiberty – library of utility functions used by GNU programs Details It was discovered that libiberty incorrectly handled certain stringoperations. If a user or automated system were tricked into processing aspecially crafted binary, a remote attacker could use this issue to causelibiberty to crash, resulting in a denial of service, or possibly executearbitrary code. This issue only applied to Ubuntu 14.04 LTS and Ubuntu16.04 LTS. (CVE-2016-2226) It was discovered that libiberty incorrectly handled parsing certainbinaries. If a user or automated system were tricked into processing aspecially crafted binary, a remote attacker could use this issue to causelibiberty to crash, [ more… ]