From 8be70107efbb417f839292165ee39d07a062046f Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Sat, 13 Jan 2018 06:19:51 +0000 Subject: gentoo resync : 13.01.2018 --- metadata/glsa/glsa-201801-12.xml | 62 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 62 insertions(+) create mode 100644 metadata/glsa/glsa-201801-12.xml (limited to 'metadata/glsa/glsa-201801-12.xml') diff --git a/metadata/glsa/glsa-201801-12.xml b/metadata/glsa/glsa-201801-12.xml new file mode 100644 index 000000000000..f97629b7f436 --- /dev/null +++ b/metadata/glsa/glsa-201801-12.xml @@ -0,0 +1,62 @@ + + + + icoutils: Multiple vulnerabilities + Multiple vulnerabilities have been found in icoutils, the worst of + which may lead to arbitrary code execution. + + icoutils + 2018-01-11 + 2018-01-11: 1 + 605138 + local, remote + + + 0.32.0 + 0.32.0 + + + +

A set of command-line programs for extracting and converting images in + Microsoft Windows(R) icon and cursor files. +

+
+ +

Multiple vulnerabilities have been discovered in icoutils. Please review + the CVE identifiers referenced below for details. +

+
+ +

A remote attacker could entice a user to process a specially crafted + file, possibly resulting in execution of arbitrary code with the + privileges of the process or a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All icoutils users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=media-gfx/icoutils-0.32.0" + +
+ + + CVE-2017-5208 + + + CVE-2017-6009 + + + CVE-2017-6010 + + + CVE-2017-6011 + + + jmbailey + b-man +
-- cgit v1.2.3