GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Wed Jul 12, 2017 4:26 am Post subject: [ GLSA 201707-02 ] Game Music Emu |
|
|
Gentoo Linux Security Advisory
Title: Game Music Emu: Multiple vulnerabilities (GLSA 201707-02)
Severity: normal
Exploitable: remote
Date: 2017-07-08
Updated: 2017-08-06
Bug(s): #603092
ID: 201707-02
Synopsis
Multiple vulnerabilities have been found in Game Music Emu, the
worst of which could lead to the execution of arbitrary code.
Background
Game Music Emu is a multi-purpose console music emulator and player
library.
Affected Packages
Package: media-libs/game-music-emu
Vulnerable: < 0.6.1
Unaffected: >= 0.6.1
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Game Music Emu. Please
review the CVE identifiers referenced below for details.
Impact
A remote attacker could entice a user to open a specially crafted SPC
music file, using Game Music Emu or an application linked against the
Game Music Emu library, possibly resulting in execution of arbitrary code
with the privileges of the process or a Denial of Service condition.
Workaround
There is no known workaround at this time.
Resolution
All Game Music Emu users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/game-music-emu-0.6.1"
|
References
CVE-2016-9957
CVE-2016-9958
CVE-2016-9959
CVE-2016-9960
CVE-2016-9961
Last edited by GLSA on Fri Sep 29, 2017 4:16 am; edited 2 times in total |
|