From f6a034d922bf54efeaa781fcb5388b325b90d945 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Wed, 3 May 2023 11:25:07 +0100 Subject: gentoo auto-resync : 03:05:2023 - 11:25:06 --- metadata/glsa/glsa-202305-01.xml | 52 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 52 insertions(+) create mode 100644 metadata/glsa/glsa-202305-01.xml (limited to 'metadata/glsa/glsa-202305-01.xml') diff --git a/metadata/glsa/glsa-202305-01.xml b/metadata/glsa/glsa-202305-01.xml new file mode 100644 index 000000000000..073b217db7a0 --- /dev/null +++ b/metadata/glsa/glsa-202305-01.xml @@ -0,0 +1,52 @@ + + + + AtomicParsley: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in AtomicParsley, the worst of which could result in arbitrary code execution. + atomicparsley,atomicparsley-wez + 2023-05-03 + 2023-05-03 + 806845 + remote + + + 0.9.6_p20210715_p151551 + 0.9.6_p20210715_p151551 + + + None + + + +

AtomicParsley is a command line program for manipulating iTunes-style metadata in MPEG4 files.

+
+ +

Multiple vulnerabilities have been discovered in AtomicParsley. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

Users can pass only trusted input to AtomicParsley.

+
+ +

Previously, the "wez" AtomicParsley fork was packaged in Gentoo as media-video/atomicparsley-wez. This fork is now packaged as media-video/atomicparsley, so users of the fork's package should now depclean it:

+ + + # emerge --ask --depclean "media-video/atomicparsley-wez" + + +

All AtomicParsley users should upgrade to the latest version, which is a packaging of the "wez" AtomicParsley fork:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=media-video/atomicparsley-0.9.6_p20210715_p151551" + +
+ + CVE-2021-37231 + CVE-2021-37232 + + ajak + sam +
\ No newline at end of file -- cgit v1.2.3