Bug 156693 - gnome-extra/libgsf buffer overflow (CVE-2006-4514)
|
Bug#:
156693
|
Product: Gentoo Security
|
Version: unspecified
|
Platform: All
|
|
OS/Version: Linux
|
Status: RESOLVED
|
Severity: normal
|
Priority: P2
|
|
Resolution: FIXED
|
Assigned To: security@gentoo.org
|
Reported By: jaervosz@gentoo.org
|
|
Component: Vulnerabilities
|
|
|
URL:
http://www.debian.org/security/2006/dsa-1221
|
|
Summary: gnome-extra/libgsf buffer overflow (CVE-2006-4514)
|
|
Keywords:
|
|
Status Whiteboard: B2 [glsa] DerCorny
|
|
Opened: 2006-11-30 09:18 0000
|
"infamous41md" discovered a heap buffer overflow vulnerability in libgsf, a
GNOME library for reading and writing structured file formats, which could lead
to the execution of arbitrary code.
libgsf 1.14.2 was already in portage and since there are no open issues
concerning it, I see no problem putting it up for stabilisation.
arches, please test and stable libgsf-1.14.2. thanks!
@Stefan, perhaps it is easer for arches if we actually call them ;-)
Target keywords are:
libgsf-1.14.2.ebuild:KEYWORDS="alpha amd64 arm hppa ia64 ppc ppc64 sh sparc
x86"
Alpha gives a bit of love here.