Gentoo Archives: gentoo-announce

From: Mikle Kolyada <zlogene@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201507-04 ] International Components for Unicode: Multiple vulnerabilities
Date: Tue, 07 Jul 2015 06:58:56
Message-Id: 559B77B0.6010307@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201507-04
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: International Components for Unicode: Multiple
9 vulnerabilities
10 Date: July 07, 2015
11 Bugs: #546156
12 ID: 201507-04
13
14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
15
16 Synopsis
17 ========
18
19 Multiple vulnerabilities have been found in International Components
20 for Unicode, allowing attackers to execute arbitrary code or cause a
21 Denial of Service condition.
22
23 Background
24 ==========
25
26 International Components for Unicode is a set of C/C++ and Java
27 libraries providing Unicode and Globalization support for software
28 applications.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 dev-libs/icu < 55.1 >= 55.1
37
38 Description
39 ===========
40
41 Multiple vulnerabilities have been discovered in International
42 Components for Unicode. Please review the CVE identifiers referenced
43 below for details.
44
45 Impact
46 ======
47
48 A remote attacker could execute arbitrary code with the privileges of
49 the process or cause a Denial of Service condition.
50
51 Workaround
52 ==========
53
54 There is no known workaround at this time.
55
56 Resolution
57 ==========
58
59 All International Components for Unicode users should upgrade to the
60 latest version:
61
62 # emerge --sync
63 # emerge --ask --oneshot --verbose ">=dev-libs/icu-55.1"
64
65 References
66 ==========
67
68 [ 1 ] CVE-2014-8146
69 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8146
70 [ 2 ] CVE-2014-8147
71 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8147
72
73 Availability
74 ============
75
76 This GLSA and any updates to it are available for viewing at
77 the Gentoo Security Website:
78
79 https://security.gentoo.org/glsa/201507-04
80
81 Concerns?
82 =========
83
84 Security is a primary focus of Gentoo Linux and ensuring the
85 confidentiality and security of our users' machines is of utmost
86 importance to us. Any security concerns should be addressed to
87 security@g.o or alternatively, you may file a bug at
88 https://bugs.gentoo.org.
89
90 License
91 =======
92
93 Copyright 2015 Gentoo Foundation, Inc; referenced text
94 belongs to its owner(s).
95
96 The contents of this document are licensed under the
97 Creative Commons - Attribution / Share Alike license.
98
99 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature