Gentoo Archives: gentoo-announce

From: Thomas Deutschmann <whissi@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201701-63 ] Graphite: Multiple vulnerabilities
Date: Tue, 24 Jan 2017 16:43:09
Message-Id: cfa104ab-85e4-fcd5-c081-bd4fecedaaf8@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201701-63
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Graphite: Multiple vulnerabilities
9 Date: January 24, 2017
10 Bugs: #574276, #576864
11 ID: 201701-63
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Graphite, the worst of
19 which could lead to the remote execution of arbitrary code.
20
21 Background
22 ==========
23
24 Graphite is a "smart font" system developed specifically to handle the
25 complexities of lesser-known languages of the world.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 media-gfx/graphite2 < 1.3.7 >= 1.3.7
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in Graphite. Please
39 review the CVE identifiers referenced below for details.
40
41 Impact
42 ======
43
44 A remote attacker could possibly execute arbitrary code with the
45 privileges of the process, cause a Denial of Service condition, or
46 obtain sensitive information.
47
48 Workaround
49 ==========
50
51 There is no known workaround at this time.
52
53 Resolution
54 ==========
55
56 All Graphite users should upgrade to the latest version:
57
58 <code>
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=media-gfx/graphite2-1.3.7"
61
62 References
63 ==========
64
65 [ 1 ] CVE-2016-1521
66 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1521
67 [ 2 ] CVE-2016-1522
68 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1522
69 [ 3 ] CVE-2016-1523
70 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1523
71 [ 4 ] CVE-2016-1526
72 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1526
73 [ 5 ] CVE-2016-1977
74 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1977
75 [ 6 ] CVE-2016-2790
76 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2790
77 [ 7 ] CVE-2016-2791
78 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2791
79 [ 8 ] CVE-2016-2792
80 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2792
81 [ 9 ] CVE-2016-2793
82 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2793
83 [ 10 ] CVE-2016-2794
84 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2794
85 [ 11 ] CVE-2016-2795
86 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2795
87 [ 12 ] CVE-2016-2796
88 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2796
89 [ 13 ] CVE-2016-2797
90 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2797
91 [ 14 ] CVE-2016-2798
92 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2798
93 [ 15 ] CVE-2016-2799
94 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2799
95 [ 16 ] CVE-2016-2800
96 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2800
97 [ 17 ] CVE-2016-2801
98 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2801
99 [ 18 ] CVE-2016-2802
100 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2802
101
102 Availability
103 ============
104
105 This GLSA and any updates to it are available for viewing at
106 the Gentoo Security Website:
107
108 https://security.gentoo.org/glsa/201701-63
109
110 Concerns?
111 =========
112
113 Security is a primary focus of Gentoo Linux and ensuring the
114 confidentiality and security of our users' machines is of utmost
115 importance to us. Any security concerns should be addressed to
116 security@g.o or alternatively, you may file a bug at
117 https://bugs.gentoo.org.
118
119 License
120 =======
121
122 Copyright 2017 Gentoo Foundation, Inc; referenced text
123 belongs to its owner(s).
124
125 The contents of this document are licensed under the
126 Creative Commons - Attribution / Share Alike license.
127
128 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature