GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Fri Dec 12, 2014 3:26 am Post subject: [ GLSA 201412-11 ] AMD64 x86 emulation base libraries: Multi |
|
|
Gentoo Linux Security Advisory
Title: AMD64 x86 emulation base libraries: Multiple vulnerabilities (GLSA 201412-11)
Severity: normal
Exploitable: local, remote
Date: December 12, 2014
Bug(s): #196865, #335508, #483632, #508322
ID: 201412-11
Synopsis
Multiple vulnerabilities have been found in AMD64 x86 emulation
base libraries, the worst of which may allow remote execution of arbitrary
code.
Background
AMD64 x86 emulation base libraries provides pre-compiled 32-bit
libraries.
Affected Packages
Package: app-emulation/emul-linux-x86-baselibs
Vulnerable: < 20140406-r1
Unaffected: >= 20140406-r1
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in AMD64 x86 emulation
base libraries. Please review the CVE identifiers referenced below for
details.
Impact
A context-dependent attacker may be able to execute arbitrary code,
cause a Denial of Service condition, or obtain sensitive information.
Workaround
There is no known workaround at this time.
Resolution
All users of the AMD64 x86 emulation base libraries should upgrade to
the latest version:
Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=app-emulation/emul-linux-x86-baselibs-20140406-r1"
| NOTE: One or more of the issues described in this advisory have been
fixed in previous updates. They are included in this advisory for the
sake of completeness. It is likely that your system is already no longer
affected by them.
References
CVE-2007-0720
CVE-2007-1536
CVE-2007-2026
CVE-2007-2445
CVE-2007-2741
CVE-2007-3108
CVE-2007-4995
CVE-2007-5116
CVE-2007-5135
CVE-2007-5266
CVE-2007-5268
CVE-2007-5269
CVE-2007-5849
CVE-2010-1205
CVE-2013-0338
CVE-2013-0339
CVE-2013-1664
CVE-2013-1969
CVE-2013-2877
CVE-2014-0160 |
|