-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 05 Jul 2016 18:18:56 +1000 Source: binutils Binary: binutils binutils-dev binutils-multiarch binutils-gold binutils-hppa64 binutils-spu binutils-doc binutils-source Architecture: source all i386 Version: 2.22-8+deb7u3 Distribution: wheezy-security Urgency: high Maintainer: Matthias Klose <doko@debian.org> Changed-By: Brian May <bam@debian.org> Description: binutils - GNU assembler, linker and binary utilities binutils-dev - GNU binary utilities (BFD development files) binutils-doc - Documentation for the GNU assembler, linker and binary utilities binutils-gold - GNU gold linker utility binutils-hppa64 - GNU assembler, linker and binary utilities targeted for hppa64-li binutils-multiarch - Binary utilities that support multi-arch targets binutils-source - GNU assembler, linker and binary utilities (source) binutils-spu - GNU assembler, linker and binary utilities targeted for spu-elf Changes: binutils (2.22-8+deb7u3) wheezy-security; urgency=high . * Non-maintainer upload by the LTS Team. * Fixes for the following CVEs: * CVE-2016-2226.patch: Exploitable buffer overflow * CVE-2016-4487.patch: Invalid write due to a use-after-free to array btypevec * CVE-2016-4488.patch: Invalid write due to a use-after-free to array ktypevec * CVE-2016-4489.patch: Invalid write due to integer overflow * CVE-2016-4490-1.patch: Write access violation * CVE-2016-4490-2.patch: Write access violation * CVE-2016-4492_CVE-2016-4493.patch: Read/write access violations * CVE-2016-6131.patch: Libiberty Demangler segfaults * CVE-2016-XXXX.patch: Stack buffer overflow when printing bad bytes in Intel Hex objects Checksums-Sha1: 37ba7a0530e95485209e52b0fd562bc0cd1f3289 2341 binutils_2.22-8+deb7u3.dsc 0e16a7492c0a194962ecd33fc80fa53ccfec5149 26843686 binutils_2.22.orig.tar.gz 6a1dd04a5e73859eb516629474fdd3da82c36feb 174687 binutils_2.22-8+deb7u3.diff.gz 2e049a6cc268eb460acab97a3076ed2517ea85bf 582100 binutils-doc_2.22-8+deb7u3_all.deb 5f914535e245df1c9e4c5ef2bd865915eef1ab85 14833954 binutils-source_2.22-8+deb7u3_all.deb 50d1696f738f6ef10ef810ca4b149e05478c3bf4 4565252 binutils_2.22-8+deb7u3_i386.deb 3f70754d87cdaa8e927057b760eaa87692a4b719 4334200 binutils-dev_2.22-8+deb7u3_i386.deb af06f9136f119a55e01dd09d347fab047cdbbaf5 2242618 binutils-multiarch_2.22-8+deb7u3_i386.deb 5564adae4c0bbf773279f9b001ae48759de0be47 1398 binutils-gold_2.22-8+deb7u3_i386.deb Checksums-Sha256: a37ff3238f66395ec06f1633fe3a1fd204981cf249337b7c17a5864b48a8de87 2341 binutils_2.22-8+deb7u3.dsc 12c26349fc7bb738f84b9826c61e103203187ca2d46f08b82e61e21fcbc6e3e6 26843686 binutils_2.22.orig.tar.gz e4d79d884f012c449734f6f8febcf997b12144bb9ccce5bfe22e338660177da9 174687 binutils_2.22-8+deb7u3.diff.gz c79acde91ae6983c69f887d06af360f7f856031572c6655e022637f7c9e1ff54 582100 binutils-doc_2.22-8+deb7u3_all.deb 2fa31ed1bd28b74620726cd12a08893b43252ec1c6bd87847fc6c97c82b92a3d 14833954 binutils-source_2.22-8+deb7u3_all.deb e6e9a02d936699fb0bb9f205437ade651594a84cfd79e0305d410cf561251556 4565252 binutils_2.22-8+deb7u3_i386.deb 6f7801d78493570686d355750d96c015f357c61e7e91211a03759c385c01119a 4334200 binutils-dev_2.22-8+deb7u3_i386.deb c4042cf657c68014730c7ff587b6efc5448647d6ea2fd7702145e98ab8a044ff 2242618 binutils-multiarch_2.22-8+deb7u3_i386.deb 9baa51ae2cf3090f75e0ebe9c5c289e99377eb21ea3a937d9145213d5dd4b53c 1398 binutils-gold_2.22-8+deb7u3_i386.deb Files: 4e9e84ff1c7148369beab375c75e6394 2341 devel optional binutils_2.22-8+deb7u3.dsc 8b3ad7090e3989810943aa19103fdb83 26843686 devel optional binutils_2.22.orig.tar.gz a602d28ba1fd191faf522f90d2b7400d 174687 devel optional binutils_2.22-8+deb7u3.diff.gz 6547fea704e209286f91dba6d4c37d9d 582100 doc optional binutils-doc_2.22-8+deb7u3_all.deb ba0eedcf9bea87c3c1a5f2aa301a2943 14833954 devel optional binutils-source_2.22-8+deb7u3_all.deb 16314cefbced4d26e27dd5f4834a65fe 4565252 devel optional binutils_2.22-8+deb7u3_i386.deb b4f250d83a563a407a0afa7675688edf 4334200 devel extra binutils-dev_2.22-8+deb7u3_i386.deb 5ab73602def01c00f15dc634ef71a88e 2242618 devel extra binutils-multiarch_2.22-8+deb7u3_i386.deb 0ad2ffddee39b372b81216be195d1631 1398 devel extra binutils-gold_2.22-8+deb7u3_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJXjIUlAAoJEBeEV3+BH26snnAP/jsp+oEkidnXJpy1FRomxfyN aIldF2z3MoBk8kD+ujvAVwDwLPu5Kgc0+dbNyKXrOQmhZlF0h55GXCtn/a5PwAM7 AbgTUJkWdUw+++3DHYf803VhbGU+eFgYt93ckLeJF3Q3jakCRuyZG9f/WCO+79O4 yF1MEzhjcitkxPi5FA3Qa5CLKntisMdOOXd27rIGyVyOrIGK8g5NHiUdMYwDXX5d 41fuNazKKQ6RjNkgepIXsvST5Q/bJrwVaKBnF7/7ZbOfJZa8CjiSA8RBKNw1kWn7 0ty5Imt5mug2fquLNblOz0l13lHdrfV22B4dmW7UeiVZOkr10bkq3mkARiV+tDkw pIG9cb6/cMw77q2pEbzWcmSgLKLWxE64pkmPFJb0S66mPZEKgigz7VWXnnxT7P7I UnMkXj1d0XfYKVZVpgRUUtXeAyQT2jsYYL4RvPAZLazZ5IcMGZa91QnYGN6hrYPC Dws9Qsx9I3KKxKiSwu2o3ckcN8P53FadgITugPg0eXVv6rQV6jvPC5hvCJAYJl5T QcnR3MnM3koc5PS01OjZg8DFk8//aMc/wVgZeEJTmaKyfq7U2caS9JObZRWONAvI 2VxxsGYDcpJ1Bscu0AyUHkat2JoOhUyk2nTz/ltIg5vSiVmu2/aS/y/JV5pLGTMf QmQGKDgkeQbTngRNwwMr =En0A -----END PGP SIGNATURE-----