Gentoo Archives: gentoo-announce

From: Thomas Deutschmann <whissi@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202005-10 ] libmicrodns: Multiple vulnerabilities
Date: Thu, 14 May 2020 22:23:46
Message-Id: ea8711d8-120b-bae7-2e03-9b4f3297870a@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202005-10
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: libmicrodns: Multiple vulnerabilities
9 Date: May 14, 2020
10 Bugs: #714606
11 ID: 202005-10
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in libmicrodns, the worst of
19 which could result in the arbitrary execution of code.
20
21 Background
22 ==========
23
24 libmicrodns is an mDNS library, focused on being simple and
25 cross-platform.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 net-libs/libmicrodns < 0.1.2 >= 0.1.2
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in libmicrodns. Please
39 review the CVE identifiers and the upstream advisory referenced below
40 for details.
41
42 Impact
43 ======
44
45 Please review the referenced CVE identifiers for details.
46
47 Workaround
48 ==========
49
50 There is no known workaround at this time.
51
52 Resolution
53 ==========
54
55 All libmicrodns users should upgrade to the latest version:
56
57 # emerge --sync
58 # emerge --ask --oneshot --verbose ">=net-libs/libmicrodns-0.1.2"
59
60 References
61 ==========
62
63 [ 1 ] CVE-2020-6071
64 https://nvd.nist.gov/vuln/detail/CVE-2020-6071
65 [ 2 ] CVE-2020-6072
66 https://nvd.nist.gov/vuln/detail/CVE-2020-6072
67 [ 3 ] CVE-2020-6073
68 https://nvd.nist.gov/vuln/detail/CVE-2020-6073
69 [ 4 ] CVE-2020-6077
70 https://nvd.nist.gov/vuln/detail/CVE-2020-6077
71 [ 5 ] CVE-2020-6078
72 https://nvd.nist.gov/vuln/detail/CVE-2020-6078
73 [ 6 ] CVE-2020-6079
74 https://nvd.nist.gov/vuln/detail/CVE-2020-6079
75 [ 7 ] CVE-2020-6080
76 https://nvd.nist.gov/vuln/detail/CVE-2020-6080
77 [ 8 ] VideoLAN-SB-VLC-309
78 https://www.videolan.org/security/sb-vlc309.html
79
80 Availability
81 ============
82
83 This GLSA and any updates to it are available for viewing at
84 the Gentoo Security Website:
85
86 https://security.gentoo.org/glsa/202005-10
87
88 Concerns?
89 =========
90
91 Security is a primary focus of Gentoo Linux and ensuring the
92 confidentiality and security of our users' machines is of utmost
93 importance to us. Any security concerns should be addressed to
94 security@g.o or alternatively, you may file a bug at
95 https://bugs.gentoo.org.
96
97 License
98 =======
99
100 Copyright 2020 Gentoo Foundation, Inc; referenced text
101 belongs to its owner(s).
102
103 The contents of this document are licensed under the
104 Creative Commons - Attribution / Share Alike license.
105
106 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature