From a24567fbc43f221b14e805f9bc0b7c6d16911c46 Mon Sep 17 00:00:00 2001 From: Alex Legler Date: Sun, 8 Mar 2015 22:02:38 +0100 Subject: Import existing advisories --- glsa-201401-12.xml | 65 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 65 insertions(+) create mode 100644 glsa-201401-12.xml (limited to 'glsa-201401-12.xml') diff --git a/glsa-201401-12.xml b/glsa-201401-12.xml new file mode 100644 index 00000000..19308f86 --- /dev/null +++ b/glsa-201401-12.xml @@ -0,0 +1,65 @@ + + + + + + GNUstep Base library: Multiple vulnerabilities + Multiple vulnerabilities have been found in GNUstep Base library, + the worst of which allow execution of arbitrary code. + + gnustep-base + January 20, 2014 + January 20, 2014: 1 + 325577 + local, remote + + + 1.20.1 + 1.20.1 + + + +

GNUstep Base library is a free software package implementing the API of + the OpenStep Foundation Kit (tm), including later additions. +

+
+ +

Multiple vulnerabilities have been discovered in GNUstep Base library. + Please review the CVE identifiers referenced below for details. +

+
+ +

A context-dependent attacker could possibly execute arbitrary code. A + local attacker could possibly read arbitrary files. +

+
+ +

There is no known workaround at this time.

+
+ +

All GNUstep Base library users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=gnustep-base/gnustep-base-1.20.1" + + +

Packages which depend on this library may need to be recompiled. Tools + such as revdep-rebuild may assist in identifying some of these packages. +

+ +

NOTE: This is a legacy GLSA. Updates for all affected architectures are + available since August 13, 2010. It is likely that your system is already + no longer affected by this issue. +

+
+ + CVE-2010-1457 + CVE-2010-1620 + + + underling + + Zlogene +
-- cgit v1.2.3-65-gdbad