UbuntuUpdates.org

Package "debuginfod"

Name: debuginfod

Description:

debuginfo-related http file-server daemon

Latest version: 0.186-1ubuntu0.1
Release: jammy (22.04)
Level: security
Repository: universe
Head package: elfutils
Homepage: https://sourceware.org/elfutils/

Links


Download "debuginfod"


Other versions of "debuginfod" in Jammy

Repository Area Version
base universe 0.186-1build1
updates universe 0.186-1ubuntu0.1
backports universe 0.188-1~bpo22.04.1

Changelog

Version: 0.186-1ubuntu0.1 2025-03-25 00:06:58 UTC

  elfutils (0.186-1ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: null pointer dereference
    - debian/patches/CVE-2025-1372.patch: Skip trying to uncompress
      sections without a name.
    - CVE-2025-1372
  * SECURITY UPDATE: null pointer dereference
    - debian/patches/CVE-2025-1377.patch: Verify symbol table is a real
      symbol table.
    - CVE-2025-1377

 -- Fabian Toepfer <email address hidden> Mon, 17 Mar 2025 17:11:50 +0100

CVE-2025-1372 A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/p
CVE-2025-1377 A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the f



About   -   Send Feedback to @ubuntu_updates