From 02e2208f46f4e2c00fb9743cbc47350bdd233bfa Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Tue, 16 Jan 2018 17:34:21 +0000 Subject: gentoo resync : 16.01.2018 --- metadata/glsa/glsa-201801-15.xml | 54 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 54 insertions(+) create mode 100644 metadata/glsa/glsa-201801-15.xml (limited to 'metadata/glsa/glsa-201801-15.xml') diff --git a/metadata/glsa/glsa-201801-15.xml b/metadata/glsa/glsa-201801-15.xml new file mode 100644 index 000000000000..6e5669c87459 --- /dev/null +++ b/metadata/glsa/glsa-201801-15.xml @@ -0,0 +1,54 @@ + + + + PolarSSL: Multiple vulnerabilities + Multiple vulnerabilities have been found in PolarSSL, the worst of + which may allow remote attackers to execute arbitrary code. + + polarssl + 2018-01-15 + 2018-01-15 + 537108 + 620504 + remote + + + 1.3.9-r1 + + + +

PolarSSL is a cryptographic library for embedded systems.

+
+ +

Multiple vulnerabilities have been discovered in PolarSSL. Please review + the CVE identifiers referenced below for details. +

+
+ +

A remote attacker might be able to execute arbitrary code, cause Denial + of Service condition or obtain sensitive information. +

+
+ +

There is no known workaround at this time.

+
+ +

Gentoo has discontinued support for PolarSSL and recommends that users + unmerge the package: +

+ + + # emerge --unmerge "net-libs/polarssl" + +
+ + + CVE-2015-1182 + + + CVE-2015-7575 + + + jmbailey + jmbailey +
-- cgit v1.2.3