Explore top 10 tips to secure your open-source projects now. Read More
×
Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which can lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202505-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Mozilla Firefox: Multiple Vulnerabilities Date: May 12, 2025 Bugs: #951563, #953021 ID: 202505-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which can lead to arbitrary code execution. Background ========== Mozilla Firefox is a popular open-source web browser from the Mozilla project. Affected packages ================= Package Vulnerable Unaffected ---------------------- ---------------- ----------------- www-client/firefox < 128.9.0:esr > = 128.9.0:esr < 137.0.1:stable > = 137.0.1:stable www-client/firefox-bin < 128.9.0:esr > = 128.9.0:esr < 137.0.1:stable > = 137.0.1:stable Description =========== Multiple vulnerabilities have been discovered in Mozilla Firefox. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Mozilla Firefox users should upgrade to the latest version in their release channel: # emerge --sync # emerge --ask --oneshot --verbose "> =www-client/firefox-bin-137.0.1:rapid" # emerge --ask --oneshot --verbose "> =www-client/firefox-bin-128.9.0:esr" All Mozilla Firefox users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-client/firefox-137.0.1:rapid" # emerge --ask --oneshot --verbose "> =www-client/firefox-128.9.0:esr" References ========== [ 1 ] CVE-2024-43097 https://nvd.nist.gov/vuln/detail/CVE-2024-43097 [ 2 ] CVE-2025-1931 https://nvd.nist.gov/vuln/detail/CVE-2025-1931 [ 3 ] CVE-2025-1932 https://nvd.nist.gov/vuln/detail/CVE-2025-1932 [ 4 ] CVE-2025-1933 https://nvd.nist.gov/vuln/detail/CVE-2025-1933 [ 5 ] CVE-2025-1934 https://nvd.nist.gov/vuln/detail/CVE-2025-1934 [ 6 ] CVE-2025-1935 https://nvd.nist.gov/vuln/detail/CVE-2025-1935 [ 7 ] CVE-2025-1936 https://nvd.nist.gov/vuln/detail/CVE-2025-1936 [ 8 ] CVE-2025-1937 https://nvd.nist.gov/vuln/detail/CVE-2025-1937 [ 9 ] CVE-2025-1938 https://nvd.nist.gov/vuln/detail/CVE-2025-1938 [ 10 ] CVE-2025-1941 https://nvd.nist.gov/vuln/detail/CVE-2025-1941 [ 11 ] CVE-2025-1942 https://nvd.nist.gov/vuln/detail/CVE-2025-1942 [ 12 ] CVE-2025-1943 https://nvd.nist.gov/vuln/detail/CVE-2025-1943 [ 13 ] CVE-2025-3028 https://nvd.nist.gov/vuln/detail/CVE-2025-3028 [ 14 ] CVE-2025-3029 https://nvd.nist.gov/vuln/detail/CVE-2025-3029 [ 15 ] CVE-2025-3030 https://nvd.nist.gov/vuln/detail/CVE-2025-3030 [ 16 ] CVE-2025-3031 https://nvd.nist.gov/vuln/detail/CVE-2025-3031 [ 17 ] CVE-2025-3032 https://nvd.nist.gov/vuln/detail/CVE-2025-3032 [ 18 ] CVE-2025-3034 https://nvd.nist.gov/vuln/detail/CVE-2025-3034 [ 19 ] CVE-2025-3035 https://nvd.nist.gov/vuln/detail/CVE-2025-3035 [ 20 ] MFSA2025-14 [ 21 ] MFSA2025-16 [ 22 ] MFSA2025-18 [ 23 ] MFSA2025-20 [ 24 ] MFSA2025-22 [ 25 ] MFSA2025-23 [ 26 ] MFSA2025-24 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202505-02 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressedto
Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202501-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: QtWebEngine: Multiple Vulnerabilities Date: January 23, 2025 Bugs: #944807 ID: 202501-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to arbitrary code execution. Background ========== QtWebEngine is a library for rendering dynamic web content in Qt5 and Qt6 C++ and QML applications. Affected packages ================= Package Vulnerable Unaffected ------------------ ------------------- -------------------- dev-qt/qtwebengine < 5.15.16_p20241115 > = 5.15.16_p20241115 Description =========== Multiple vulnerabilities have been discovered in QtWebEngine. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All QtWebEngine users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-qt/qtwebengine-5.15.16_p20241115" References ========== [ 1 ] CVE-2024-4058 https://nvd.nist.gov/vuln/detail/CVE-2024-4058 [ 2 ] CVE-2024-4059 https://nvd.nist.gov/vuln/detail/CVE-2024-4059 [ 3 ] CVE-2024-4060 https://nvd.nist.gov/vuln/detail/CVE-2024-4060 [ 4 ] CVE-2024-4558 https://nvd.nist.gov/vuln/detail/CVE-2024-4558 [ 5 ] CVE-2024-4559 https://nvd.nist.gov/vuln/detail/CVE-2024-4559 [ 6 ]CVE-2024-4761 https://nvd.nist.gov/vuln/detail/CVE-2024-4761 [ 7 ] CVE-2024-5157 https://nvd.nist.gov/vuln/detail/CVE-2024-5157 [ 8 ] CVE-2024-5158 https://nvd.nist.gov/vuln/detail/CVE-2024-5158 [ 9 ] CVE-2024-5159 https://nvd.nist.gov/vuln/detail/CVE-2024-5159 [ 10 ] CVE-2024-5160 https://nvd.nist.gov/vuln/detail/CVE-2024-5160 [ 11 ] CVE-2024-5830 https://nvd.nist.gov/vuln/detail/CVE-2024-5830 [ 12 ] CVE-2024-5831 https://nvd.nist.gov/vuln/detail/CVE-2024-5831 [ 13 ] CVE-2024-5832 https://nvd.nist.gov/vuln/detail/CVE-2024-5832 [ 14 ] CVE-2024-5833 https://nvd.nist.gov/vuln/detail/CVE-2024-5833 [ 15 ] CVE-2024-5834 https://nvd.nist.gov/vuln/detail/CVE-2024-5834 [ 16 ] CVE-2024-5835 https://nvd.nist.gov/vuln/detail/CVE-2024-5835 [ 17 ] CVE-2024-5836 https://nvd.nist.gov/vuln/detail/CVE-2024-5836 [ 18 ] CVE-2024-5837 https://nvd.nist.gov/vuln/detail/CVE-2024-5837 [ 19 ] CVE-2024-5838 https://nvd.nist.gov/vuln/detail/CVE-2024-5838 [ 20 ] CVE-2024-5839 https://nvd.nist.gov/vuln/detail/CVE-2024-5839 [ 21 ] CVE-2024-5840 https://nvd.nist.gov/vuln/detail/CVE-2024-5840 [ 22 ] CVE-2024-5841 https://nvd.nist.gov/vuln/detail/CVE-2024-5841 [ 23 ] CVE-2024-5842 https://nvd.nist.gov/vuln/detail/CVE-2024-5842 [ 24 ] CVE-2024-5843 https://nvd.nist.gov/vuln/detail/CVE-2024-5843 [ 25 ] CVE-2024-5844 https://nvd.nist.gov/vuln/detail/CVE-2024-5844 [ 26 ] CVE-2024-5845 https://nvd.nist.gov/vuln/detail/CVE-2024-5845 [ 27 ] CVE-2024-5846 https://nvd.nist.gov/vuln/detail/CVE-2024-5846 [ 28 ] CVE-2024-5847 https://nvd.nist.gov/vuln/detail/CVE-2024-5847 [ 29 ] CVE-2024-6290 https://nvd.nist.gov/vuln/detail/CVE-2024-6290 [ 30 ] CVE-2024-6291 https://nvd.nist.gov/vuln/detail/CVE-2024-6291 [ 31 ] CVE-2024-6292 https://nvd.nist.gov/vuln/detail/CVE-2024-6292 [ 32 ] CVE-2024-6293 https://nvd.nist.gov/vuln/detail/CVE-2024-6293 [ 33 ] CVE-2024-6988 https://nvd.nist.gov/vuln/detail/CVE-2024-6988 [ 34 ] CVE-2024-6989 https://nvd.nist.gov/vuln/detail/CVE-2024-6989 [ 35 ] CVE-2024-6991 https://nvd.nist.gov/vuln/detail/CVE-2024-6991 [ 36 ] CVE-2024-6994 https://nvd.nist.gov/vuln/detail/CVE-2024-6994 [ 37 ] CVE-2024-6995 https://nvd.nist.gov/vuln/detail/CVE-2024-6995 [ 38 ] CVE-2024-6996 https://nvd.nist.gov/vuln/detail/CVE-2024-6996 [ 39 ] CVE-2024-6997 https://nvd.nist.gov/vuln/detail/CVE-2024-6997 [ 40 ] CVE-2024-6998 https://nvd.nist.gov/vuln/detail/CVE-2024-6998 [ 41 ] CVE-2024-6999 https://nvd.nist.gov/vuln/detail/CVE-2024-6999 [ 42 ] CVE-2024-7000 https://nvd.nist.gov/vuln/detail/CVE-2024-7000 [ 43 ] CVE-2024-7001 https://nvd.nist.gov/vuln/detail/CVE-2024-7001 [ 44 ] CVE-2024-7003 https://nvd.nist.gov/vuln/detail/CVE-2024-7003 [ 45 ] CVE-2024-7004 https://nvd.nist.gov/vuln/detail/CVE-2024-7004 [ 46 ] CVE-2024-7005 https://nvd.nist.gov/vuln/detail/CVE-2024-7005 [ 47 ] CVE-2024-7532 https://nvd.nist.gov/vuln/detail/CVE-2024-7532 [ 48 ] CVE-2024-7533 https://nvd.nist.gov/vuln/detail/CVE-2024-7533 [ 49 ] CVE-2024-7534 https://nvd.nist.gov/vuln/detail/CVE-2024-7534 [ 50 ] CVE-2024-7535 https://nvd.nist.gov/vuln/detail/CVE-2024-7535 [ 51 ] CVE-2024-7536 https://nvd.nist.gov/vuln/detail/CVE-2024-7536 [ 52 ] CVE-2024-7550 https://nvd.nist.gov/vuln/detail/CVE-2024-7550 [ 53 ] CVE-2024-7964 https://nvd.nist.gov/vuln/detail/CVE-2024-7964 [ 54 ] CVE-2024-7965 https://nvd.nist.gov/vuln/detail/CVE-2024-7965 [ 55 ] CVE-2024-7966 https://nvd.nist.gov/vuln/detail/CVE-2024-7966 [ 56 ] CVE-2024-7967 https://nvd.nist.gov/vuln/detail/CVE-2024-7967 [ 57 ] CVE-2024-7968 https://nvd.nist.gov/vuln/detail/CVE-2024-7968 [ 58 ] CVE-2024-7969 https://nvd.nist.gov/vuln/detail/CVE-2024-7969 [ 59 ] CVE-2024-7971 https://nvd.nist.gov/vuln/detail/CVE-2024-7971 [ 60 ] CVE-2024-7972 https://nvd.nist.gov/vuln/detail/CVE-2024-7972 [61 ] CVE-2024-7973 https://nvd.nist.gov/vuln/detail/CVE-2024-7973 [ 62 ] CVE-2024-7974 https://nvd.nist.gov/vuln/detail/CVE-2024-7974 [ 63 ] CVE-2024-7975 https://nvd.nist.gov/vuln/detail/CVE-2024-7975 [ 64 ] CVE-2024-7976 https://nvd.nist.gov/vuln/detail/CVE-2024-7976 [ 65 ] CVE-2024-7977 https://nvd.nist.gov/vuln/detail/CVE-2024-7977 [ 66 ] CVE-2024-7978 https://nvd.nist.gov/vuln/detail/CVE-2024-7978 [ 67 ] CVE-2024-7979 https://nvd.nist.gov/vuln/detail/CVE-2024-7979 [ 68 ] CVE-2024-7980 https://nvd.nist.gov/vuln/detail/CVE-2024-7980 [ 69 ] CVE-2024-7981 https://nvd.nist.gov/vuln/detail/CVE-2024-7981 [ 70 ] CVE-2024-8033 https://nvd.nist.gov/vuln/detail/CVE-2024-8033 [ 71 ] CVE-2024-8034 https://nvd.nist.gov/vuln/detail/CVE-2024-8034 [ 72 ] CVE-2024-8035 https://nvd.nist.gov/vuln/detail/CVE-2024-8035 [ 73 ] CVE-2024-8193 https://nvd.nist.gov/vuln/detail/CVE-2024-8193 [ 74 ] CVE-2024-8194 https://nvd.nist.gov/vuln/detail/CVE-2024-8194 [ 75 ] CVE-2024-8198 https://nvd.nist.gov/vuln/detail/CVE-2024-8198 [ 76 ] CVE-2024-8636 https://nvd.nist.gov/vuln/detail/CVE-2024-8636 [ 77 ] CVE-2024-8637 https://nvd.nist.gov/vuln/detail/CVE-2024-8637 [ 78 ] CVE-2024-8638 https://nvd.nist.gov/vuln/detail/CVE-2024-8638 [ 79 ] CVE-2024-8639 https://nvd.nist.gov/vuln/detail/CVE-2024-8639 [ 80 ] CVE-2024-9120 https://nvd.nist.gov/vuln/detail/CVE-2024-9120 [ 81 ] CVE-2024-9121 https://nvd.nist.gov/vuln/detail/CVE-2024-9121 [ 82 ] CVE-2024-9122 https://nvd.nist.gov/vuln/detail/CVE-2024-9122 [ 83 ] CVE-2024-9123 https://nvd.nist.gov/vuln/detail/CVE-2024-9123 [ 84 ] CVE-2024-9602 https://nvd.nist.gov/vuln/detail/CVE-2024-9602 [ 85 ] CVE-2024-9603 https://nvd.nist.gov/vuln/detail/CVE-2024-9603 [ 86 ] CVE-2024-10229 https://nvd.nist.gov/vuln/detail/CVE-2024-10229 [ 87 ] CVE-2024-10230 https://nvd.nist.gov/vuln/detail/CVE-2024-10230 [ 88 ] CVE-2024-10231 https://nvd.nist.gov/vuln/detail/CVE-2024-10231 [ 89 ] CVE-2024-10826 https://nvd.nist.gov/vuln/detail/CVE-2024-10826 [ 90 ] CVE-2024-10827 https://nvd.nist.gov/vuln/detail/CVE-2024-10827 [ 91 ] CVE-2024-45490 https://nvd.nist.gov/vuln/detail/CVE-2024-45490 [ 92 ] CVE-2024-45491 https://nvd.nist.gov/vuln/detail/CVE-2024-45491 [ 93 ] CVE-2024-45492 https://nvd.nist.gov/vuln/detail/CVE-2024-45492 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202501-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been discovered in PostgreSQL, the worst of which could lead to privilege escalation or denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202408-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: PostgreSQL: Multiple Vulnerabilities Date: August 07, 2024 Bugs: #903193, #912251, #917153, #924110, #931849 ID: 202408-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in PostgreSQL, the worst of which could lead to privilege escalation or denial of service. Background ========== PostgreSQL is an open source object-relational database management system. Affected packages ================= Package Vulnerable Unaffected ----------------- ------------- -------------- dev-db/postgresql < 12.19:12 > = 12.19:12 < 13.14:13 > = 13.14:13 < 14.12-r1:14 > = 14.12-r1:14 < 15.7-r1:15 > = 15.7-r1:15 < 16.3-r1:16 > = 16.3-r1:16 < 12 > = 12.19 Description =========== Multiple vulnerabilities have been discovered in PostgreSQL. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All PostgreSQL users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-db/postgresql-16.3-r1:16" Or update an older slot if that is still in use. References ========== [ 1 ] CVE-2023-5868 https://nvd.nist.gov/vuln/detail/CVE-2023-5868 [ 2 ]CVE-2023-5869 https://nvd.nist.gov/vuln/detail/CVE-2023-5869 [ 3 ] CVE-2023-5870 https://nvd.nist.gov/vuln/detail/CVE-2023-5870 [ 4 ] CVE-2024-0985 https://nvd.nist.gov/vuln/detail/CVE-2024-0985 [ 5 ] CVE-2024-4317 https://nvd.nist.gov/vuln/detail/CVE-2024-4317 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202408-06 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been discovered in LIVE555 Media Server, the worst of which could lead to a denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202407-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: LIVE555 Media Server: Multiple Vulnerabilities Date: July 09, 2024 Bugs: #732598, #807622 ID: 202407-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in LIVE555 Media Server, the worst of which could lead to a denial of service. Background ========== LIVE555 Media Server is a set of libraries for multimedia streaming. Affected packages ================= Package Vulnerable Unaffected ------------------ ------------ ------------- media-plugins/live < 2021.08.24 > = 2021.08.24 Description =========== Multiple vulnerabilities have been discovered in LIVE555 Media Server. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All LIVE555 Media Server users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-plugins/live-2021.08.24" References ========== [ 1 ] CVE-2020-24027 https://nvd.nist.gov/vuln/detail/CVE-2020-24027 [ 2 ] CVE-2021-38380 https://nvd.nist.gov/vuln/detail/CVE-2021-38380 [ 3 ] CVE-2021-38381 https://nvd.nist.gov/vuln/detail/CVE-2021-38381 [ 4 ] CVE-2021-38382 https://nvd.nist.gov/vuln/detail/CVE-2021-38382 [ 5 ] CVE-2021-39282 https://nvd.nist.gov/vuln/detail/CVE-2021-39282 [ 6 ] CVE-2021-39283 https://nvd.nist.gov/vuln/detail/CVE-2021-39283 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202407-23 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
A vulnerability has been discovered in Liferea, which can lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202407-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Liferea: Remote Code Execution Date: July 01, 2024 Bugs: #901085 ID: 202407-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Liferea, which can lead to remote code execution. Background ========== Liferea is a feed reader/news aggregator that brings together all of the content from your favorite subscriptions into a simple interface that makes it easy to organize and browse feeds. Its GUI is similar to a desktop mail/news client, with an embedded web browser. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ net-news/liferea < 1.12.10 > = 1.12.10 Description =========== A vulnerability has been discovered in Liferea. Please review the CVE identifier referenced below for details. Impact ====== A vulnerability was found in liferea. Affected by this issue is the function update_job_run of the file src/update.c of the component Feed Enrichment. The manipulation of the argument source can lead to os command injection. The attack may be launched remotely. Workaround ========== There is no known workaround at this time. Resolution ========== All Liferea users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-news/liferea-1.12.10" References ========== [ 1 ] CVE-2023-1350 https://nvd.nist.gov/vuln/detail/CVE-2023-1350 Availability ============ This GLSA and any updates to it are available forviewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202407-03 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been discovered in Pillow, the worst of which can lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202405-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Pillow: Multiple Vulnerabilities Date: May 05, 2024 Bugs: #889594, #903664, #916907, #922577 ID: 202405-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Pillow, the worst of which can lead to arbitrary code execution. Background ========== The friendly PIL fork. Affected packages ================= Package Vulnerable Unaffected ----------------- ------------ ------------ dev-python/pillow < 10.2.0 > = 10.2.0 Description =========== Multiple vulnerabilities have been discovered in Pillow. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Pillow users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-python/pillow-10.2.0" References ========== [ 1 ] CVE-2023-44271 https://nvd.nist.gov/vuln/detail/CVE-2023-44271 [ 2 ] CVE-2023-50447 https://nvd.nist.gov/vuln/detail/CVE-2023-50447 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202405-12 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should beaddressed to
A vulnerability has been discovered in Glade which can lead to a denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202402-27 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Glade: Denial of Service Date: February 19, 2024 Bugs: #747451 ID: 202402-27 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Glade which can lead to a denial of service. Background ========== Glade is a RAD tool to enable quick & easy development of user interfaces for the GTK+ toolkit (Version 3 only) and the GNOME desktop environment. Affected packages ================= Package Vulnerable Unaffected -------------- ------------ ------------ dev-util/glade < 3.38.2 > = 3.38.2 Description =========== A vulnerability has been found in Glade which can lead to a denial of service when working with specific glade files. Impact ====== A crafted file may lead to crashes in Glade. Workaround ========== There is no known workaround at this time. Resolution ========== All Glade users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-util/glade-3.38.2" References ========== [ 1 ] CVE-2020-36774 https://nvd.nist.gov/vuln/detail/CVE-2020-36774 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202402-27 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
A vulnerability has been discovered in GNU Tar which may lead to an out of bounds read.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202402-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: GNU Tar: Out of Bounds Read Date: February 18, 2024 Bugs: #898176 ID: 202402-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in GNU Tar which may lead to an out of bounds read. Background ========== The GNU Tar program provides the ability to create tar archives, as well as various other kinds of manipulation. Affected packages ================= Package Vulnerable Unaffected ------------ ------------ ------------ app-arch/tar < 1.34-r3 > = 1.34-r3 Description =========== A vulnerability have been discovered in GNU Tar. Please review the CVE identifier referenced below for details. Impact ====== GNU Tar has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs via a V7 archive in which mtime has approximately 11 whitespace characters. Workaround ========== There is no known workaround at this time. Resolution ========== All GNU Tar users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-arch/tar-1.34-r3" References ========== [ 1 ] CVE-2022-48303 https://nvd.nist.gov/vuln/detail/CVE-2022-48303 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202402-12 Concerns? ========= Security is a primary focus of Gentoo Linux andensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.