[ALSA-2021:4594] Moderate: gcc-toolset-11-binutils security update
Type:
security
Severity:
moderate
Release date:
2021-11-12
Description:
The binutils packages provide a collection of binary utilities for the manipulation of object code in various object file formats. It includes the ar, as, gprof, ld, nm, objcopy, objdump, ranlib, readelf, size, strings, strip, and addr2line utilities. Security Fix(es): * Developer environment: Unicode's bidirectional (BiDi) override characters can cause trojan source attacks (CVE-2021-42574) The following changes were introduced in binutils in order to facilitate detection of BiDi Unicode characters: Tools which display names or strings (readelf, strings, nm, objdump) have a new command line option --unicode / -U which controls how Unicode characters are handled. Using "--unicode=default" will treat them as normal for the tool. This is the default behaviour when --unicode option is not used. Using "--unicode=locale" will display them according to the current locale. Using "--unicode=hex" will display them as hex byte values. Using "--unicode=escape" will display them as Unicode escape sequences. Using "--unicode=highlight" will display them as Unicode escape sequences highlighted in red, if supported by the output device. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References:
Updated packages listed below:
Architecture Package Checksum
i686 gcc-toolset-11-binutils-devel-2.36.1-1.el8_5.1.i686.rpm 37ac47022901071ad73184079fd70329f681b2f7c91396aac9cb5bb237903ab5
x86_64 gcc-toolset-11-binutils-devel-2.36.1-1.el8_5.1.x86_64.rpm 04ec475ccb7f29980218876fbfcb7330e5ce196fac5bc73def4ada0584d1d485
x86_64 gcc-toolset-11-binutils-2.36.1-1.el8_5.1.x86_64.rpm 7aff7a9f672ab18bac1663511f57d63d74370c114360a62a6eb841dae9c46d26
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.