Summary: | <media-libs/libcaca-0.99_beta19-r4: multiple vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | CONFIRMED --- | ||
Severity: | minor | CC: | ajak, media-video |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B4 [glsa?] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
![]() ![]() ![]() ![]() Looks like this was addressed in: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=9e49df2222085dded48b58473bc2fd6347f8352f Interesting. There's 3 new CVEs in that commit message which aren't tracked by a Gentoo bug: CVE-2018-20544 CVE-2018-20547 CVE-2018-20549 And looks like the patch named "CVE-2018-20545+20547+20549.patch" actually fixes -20545, -20548, and -20549 according to the upstream commit message: """ Fixes: #37 (CVE-2018-20545) Fixes: #40 (CVE-2018-20548) Fixes: #41 (CVE-2018-20549) """ |