From f65628136faa35d0c4d3b5e7332275c7b35fcd96 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Sat, 3 Nov 2018 08:36:22 +0000 Subject: gentoo resync : 03.11.2018 --- metadata/glsa/glsa-201810-05.xml | 61 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 61 insertions(+) create mode 100644 metadata/glsa/glsa-201810-05.xml (limited to 'metadata/glsa/glsa-201810-05.xml') diff --git a/metadata/glsa/glsa-201810-05.xml b/metadata/glsa/glsa-201810-05.xml new file mode 100644 index 000000000000..d88bef878a13 --- /dev/null +++ b/metadata/glsa/glsa-201810-05.xml @@ -0,0 +1,61 @@ + + + + xkbcommon: Multiple vulnerabilities + Multiple vulnerabilities have been found in xkbcommon, the worst of + which may lead to a Denial of Service condition. + + libxkbcommon + 2018-10-30 + 2018-10-30 + 665702 + local + + + 0.8.2 + 0.8.2 + + + +

xkbcommon is a library to handle keyboard descriptions, including + loading them from disk, parsing them and handling their state. +

+
+ +

Multiple vulnerabilities have been discovered in libxkbcommon. Please + review the CVE identifiers referenced below for details. +

+
+ +

A local attacker could supply a specially crafted keymap file possibly + resulting in a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All libxkbcommon users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=x11-libs/libxkbcommon-0.8.2" + + +
+ + CVE-2018-15853 + CVE-2018-15854 + CVE-2018-15855 + CVE-2018-15856 + CVE-2018-15857 + CVE-2018-15858 + CVE-2018-15859 + CVE-2018-15861 + CVE-2018-15862 + CVE-2018-15863 + CVE-2018-15864 + + whissi + whissi +
-- cgit v1.2.3