From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([208.92.234.80] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1RESZO-00081Z-HJ for garchives@archives.gentoo.org; Thu, 13 Oct 2011 21:12:02 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id E77E621C025; Thu, 13 Oct 2011 21:11:52 +0000 (UTC) Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) by pigeon.gentoo.org (Postfix) with ESMTP id B076721C025 for ; Thu, 13 Oct 2011 21:11:52 +0000 (UTC) Received: from flycatcher.gentoo.org (flycatcher.gentoo.org [81.93.255.6]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.gentoo.org (Postfix) with ESMTPS id 2C3CC1B4016 for ; Thu, 13 Oct 2011 21:11:52 +0000 (UTC) Received: by flycatcher.gentoo.org (Postfix, from userid 2260) id E4D232004B; Thu, 13 Oct 2011 21:11:50 +0000 (UTC) From: "Stefan Behte (craig)" To: gentoo-commits@lists.gentoo.org Reply-To: gentoo-dev@lists.gentoo.org, craig@gentoo.org Subject: [gentoo-commits] gentoo commit in xml/htdocs/security/en/glsa: glsa-201110-08.xml X-VCS-Repository: gentoo X-VCS-Files: glsa-201110-08.xml X-VCS-Directories: xml/htdocs/security/en/glsa X-VCS-Committer: craig X-VCS-Committer-Name: Stefan Behte Content-Type: text/plain; charset=utf8 Message-Id: <20111013211150.E4D232004B@flycatcher.gentoo.org> Date: Thu, 13 Oct 2011 21:11:50 +0000 (UTC) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-commits@lists.gentoo.org Content-Transfer-Encoding: quoted-printable X-Archives-Salt: X-Archives-Hash: 3569533cabe7c24c24de87d29eb6a553 craig 11/10/13 21:11:50 Added: glsa-201110-08.xml Log: GLSA 201110-08 Revision Changes Path 1.1 xml/htdocs/security/en/glsa/glsa-201110-08.xml file : http://sources.gentoo.org/viewvc.cgi/gentoo/xml/htdocs/security/en= /glsa/glsa-201110-08.xml?rev=3D1.1&view=3Dmarkup plain: http://sources.gentoo.org/viewvc.cgi/gentoo/xml/htdocs/security/en= /glsa/glsa-201110-08.xml?rev=3D1.1&content-type=3Dtext/plain Index: glsa-201110-08.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D feh: Multiple vulnerabilities Multiple vulnerabilities were found in feh, the worst of whic= h leading to remote passive code execution. feh October 13, 2011 October 13, 2011: 2 325531 354063 local, remote 1.12 1.12

feh is a fast, lightweight imageviewer using imlib2.

Multiple vulnerabilities have been discovered in feh. Please revie= w the CVE identifiers referenced below for details.

A malicious entity might entice a user to visit a URL using the --wget-timestamp option, thus executing arbitrary commands via shel= l metacharacters; a malicious local user could perform a symlink atta= ck and overwrite arbitrary files.

There is no known workaround at this time.

All feh users should upgrade to the latest version:

=20 # emerge --sync # emerge --ask --oneshot --verbose ">=3Dmedia-gfx/feh-1.12" =20
CVE= -2010-2246 CVE= -2011-0702 CVE= -2011-1031 craig craig