Gentoo Archives: gentoo-announce

From: Pierre-Yves Rofes <py@g.o>
To: gentoo-announce@l.g.o
Cc: full-disclosure@××××××××××××××.uk, bugtraq@×××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200801-02 ] R: Multiple vulnerabilities
Date: Wed, 09 Jan 2008 20:25:28
Message-Id: 47852CCD.1040307@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200801-02:02
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: R: Multiple vulnerabilities
12 Date: January 09, 2008
13 Updated: January 09, 2008
14 Bugs: #198976
15 ID: 200801-02:02
16
17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
18
19 Synopsis
20 ========
21
22 Multiple vulnerabilities in R could result in the execution of
23 arbitrary code.
24
25 Background
26 ==========
27
28 R is a GPL licensed implementation of S, a language and environment for
29 statistical computing and graphics. PCRE is a library providing
30 functions for Perl-compatible regular expressions.
31
32 Affected packages
33 =================
34
35 -------------------------------------------------------------------
36 Package / Vulnerable / Unaffected
37 -------------------------------------------------------------------
38 1 dev-lang/R < 2.2.1-r1 >= 2.2.1-r1
39
40 Description
41 ===========
42
43 R includes a copy of PCRE which is vulnerable to multiple buffer
44 overflows and memory corruptions vulnerabilities (GLSA 200711-30).
45
46 Impact
47 ======
48
49 An attacker could entice a user to process specially crafted regular
50 expressions with R, which could possibly lead to the execution of
51 arbitrary code, a Denial of Service or the disclosure of sensitive
52 information.
53
54 Workaround
55 ==========
56
57 There is no known workaround at this time.
58
59 Resolution
60 ==========
61
62 All R users should upgrade to the latest version:
63
64 # emerge --sync
65 # emerge --ask --oneshot --verbose ">=dev-lang/R-2.2.1-r1"
66
67 References
68 ==========
69
70 [ 1 ] GLSA 200711-30
71 http://www.gentoo.org/security/en/glsa/glsa-200711-30.xml
72
73 Availability
74 ============
75
76 This GLSA and any updates to it are available for viewing at
77 the Gentoo Security Website:
78
79 http://security.gentoo.org/glsa/glsa-200801-02.xml
80
81 Concerns?
82 =========
83
84 Security is a primary focus of Gentoo Linux and ensuring the
85 confidentiality and security of our users machines is of utmost
86 importance to us. Any security concerns should be addressed to
87 security@g.o or alternatively, you may file a bug at
88 http://bugs.gentoo.org.
89
90 License
91 =======
92
93 Copyright 2008 Gentoo Foundation, Inc; referenced text
94 belongs to its owner(s).
95
96 The contents of this document are licensed under the
97 Creative Commons - Attribution / Share Alike license.
98
99 http://creativecommons.org/licenses/by-sa/2.5
100 -----BEGIN PGP SIGNATURE-----
101 Version: GnuPG v1.4.7 (GNU/Linux)
102 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
103
104 iD8DBQFHhSzNuhJ+ozIKI5gRAv/GAJ4s+FJxqDrpwUoSN19kvoaGdvTOsQCfRsyW
105 4eyDYija0jo+SnV0Fr9EvOY=
106 =C47N
107 -----END PGP SIGNATURE-----
108 --
109 gentoo-announce@l.g.o mailing list