Gentoo Archives: gentoo-announce

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201503-06 ] ICU: Multiple Vulnerabilities
Date: Sat, 14 Mar 2015 18:27:56
Message-Id: 55047CFD.5090500@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA512
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 201503-06
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 https://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: ICU: Multiple Vulnerabilities
12 Date: March 14, 2015
13 Bugs: #537560, #539108
14 ID: 201503-06
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Multiple vulnerabilities have been found in ICU, possibly resulting in
22 Denial of Service.
23
24 Background
25 ==========
26
27 ICU is a mature, widely used set of C/C++ and Java libraries providing
28 Unicode and Globalization support for software applications.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 dev-libs/icu < 54.1-r1 >= 54.1-r1
37
38 Description
39 ===========
40
41 Multiple vulnerabilities have been discovered in ICU. Please review the
42 CVE identifiers referenced below for details.
43
44 Impact
45 ======
46
47 A remote attacker can cause Denial of Service.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All ICU users should upgrade to the latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=dev-libs/icu-54.1-r1"
61
62 References
63 ==========
64
65 [ 1 ] CVE-2014-7923
66 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-7923
67 [ 2 ] CVE-2014-7926
68 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-7926
69 [ 3 ] CVE-2014-7940
70 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-7940
71 [ 4 ] CVE-2014-9654
72 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9654
73
74 Availability
75 ============
76
77 This GLSA and any updates to it are available for viewing at
78 the Gentoo Security Website:
79
80 https://security.gentoo.org/glsa/201503-06
81
82 Concerns?
83 =========
84
85 Security is a primary focus of Gentoo Linux and ensuring the
86 confidentiality and security of our users' machines is of utmost
87 importance to us. Any security concerns should be addressed to
88 security@g.o or alternatively, you may file a bug at
89 https://bugs.gentoo.org.
90
91 License
92 =======
93
94 Copyright 2015 Gentoo Foundation, Inc; referenced text
95 belongs to its owner(s).
96
97 The contents of this document are licensed under the
98 Creative Commons - Attribution / Share Alike license.
99
100 http://creativecommons.org/licenses/by-sa/2.5
101
102 -----BEGIN PGP SIGNATURE-----
103
104 iQEcBAEBCgAGBQJVBHzsAAoJEP7VAChXwav6kI0IAKSuaZebDp5x/RB9KSyev3I1
105 SLA5Q3x5F+oxfDZ2YMWddzywk5EQeV4VOWbIdBeBHjOiSBF/JQk7i/lVkjyrwgYY
106 jzeYIiBcQ7oJDcJ6RU3LpCLdxgUkQoo+dO/kIv1e+i1u5ZTR0MPWX9izCzOQmz00
107 7cwykF1AyysSx49x0DKD7JVfnMeN6R2aKrVJCrh96BWiNCOjGzJvvxens3ZXHg4g
108 KypQ6+B2ENymC5O5hIfU0d6P7Ssr6PAsL7K7i4FHupEx7eyl6VPQL2JkFLxnB8SX
109 QXztxVJWechV7HMPthkewMCwwEYL9qO0Nhf/VGe4f1HI7zEo3Nd1sqT5uO4IM44=
110 =LXuE
111 -----END PGP SIGNATURE-----