Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- Gentoo Linux Security Advisory 202312-01[6]
- Authored by Gentoo[7] | Site security.gentoo.org[8]
-
Gentoo Linux Security Advisory 202312-1 - Several vulnerabilities have been found in Leptonice, the worst of which could lead to arbitrary code execution. Versions greater than or equal to 1.81.0 are affected.
- systems | linux[9], gentoo[10]
- advisories | CVE-2017-18196[11], CVE-2018-7186[12], CVE-2018-7247[13], CVE-2018-7440[14], CVE-2018-7441[15], CVE-2018-7442[16], CVE-2022-38266[17]
- SHA-256 |
15792a867789f26ef677a41865c5d76fdd953d01a4e50faab0b867ba1464cb8b - Download[18] | Favorite[19] | View[20]
Change Mirror[21] Download[22]
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202312-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: High
Title: Leptonica: Multiple Vulnerabilities
Date: December 18, 2023
Bugs: #649752, #869416
ID: 202312-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Several vulnerabilities have been found in Leptonice, the worst of which
could lead to arbitrary code execution.
Background
==========
Leptonica is a C library for image processing and analysis.
Affected packages
=================
Package Vulnerable Unaffected
-------------------- ------------ ------------
media-libs/leptonica < 1.81.0 >= 1.81.0
Description
===========
Multiple vulnerabilities have been discovered in Leptonica. Please
review the CVE identifiers referenced below for details.
Impact
======
Please review the referenced CVE identifiers for details.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All Leptonica users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/leptonica-1.81.0"
References
==========
[ 1 ] CVE-2017-18196
https://nvd.nist.gov/vuln/detail/CVE-2017-18196
[ 2 ] CVE-2018-7186
https://nvd.nist.gov/vuln/detail/CVE-2018-7186
[ 3 ] CVE-2018-7247
https://nvd.nist.gov/vuln/detail/CVE-2018-7247
[ 4 ] CVE-2018-7440
https://nvd.nist.gov/vuln/detail/CVE-2018-7440
[ 5 ] CVE-2018-7441
https://nvd.nist.gov/vuln/detail/CVE-2018-7441
[ 6 ] CVE-2018-7442
https://nvd.nist.gov/vuln/detail/CVE-2018-7442
[ 7 ] CVE-2022-38266
https://nvd.nist.gov/vuln/detail/CVE-2022-38266
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202312-01
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser. or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2023 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
File Tags
- ActiveX[28] (932)
- Advisory[29] (83,531)
- Arbitrary[30] (16,449)
- BBS[31] (2,859)
- Bypass[32] (1,803)
- CGI[33] (1,031)
- Code Execution[34] (7,444)
- Conference[35] (683)
- Cracker[36] (843)
- CSRF[37] (3,355)
- DoS[38] (24,093)
- Encryption[39] (2,372)
- Exploit[40] (52,314)
- File Inclusion[41] (4,235)
- File Upload[42] (980)
- Firewall[43] (822)
- Info Disclosure[44] (2,812)
- Intrusion Detection[45] (900)
- Java[46] (3,091)
- JavaScript[47] (881)
- Kernel[48] (6,865)
- Local[49] (14,597)
- Magazine[50] (586)
- Overflow[51] (12,887)
- Perl[52] (1,427)
- PHP[53] (5,164)
- Proof of Concept[54] (2,354)
- Protocol[55] (3,658)
- Python[56] (1,571)
- Remote[57] (31,091)
- Root[58] (3,607)
- Rootkit[59] (516)
- Ruby[60] (614)
- Scanner[61] (1,645)
- Security Tool[62] (7,932)
- Shell[63] (3,216)
- Shellcode[64] (1,216)
- Sniffer[65] (897)
- Spoof[66] (2,231)
- SQL Injection[67] (16,454)
- TCP[68] (2,419)
- Trojan[69] (687)
- UDP[70] (896)
- Virus[71] (667)
- Vulnerability[72] (32,155)
- Web[73] (9,795)
- Whitepaper[74] (3,759)
- x86[75] (966)
- XSS[76] (18,064)
- Other[77]
File Archives
- December 2023[78]
- November 2023[79]
- October 2023[80]
- September 2023[81]
- August 2023[82]
- July 2023[83]
- June 2023[84]
- May 2023[85]
- April 2023[86]
- March 2023[87]
- February 2023[88]
- January 2023[89]
- Older[90]
Systems
- AIX[91] (429)
- Apple[92] (2,048)
- BSD[93] (375)
- CentOS[94] (57)
- Cisco[95] (1,926)
- Debian[96] (6,922)
- Fedora[97] (1,692)
- FreeBSD[98] (1,246)
- Gentoo[99] (4,380)
- HPUX[100] (880)
- iOS[101] (366)
- iPhone[102] (108)
- IRIX[103] (220)
- Juniper[104] (69)
- Linux[105] (47,995)
- Mac OS X[106] (691)
- Mandriva[107] (3,105)
- NetBSD[108] (256)
- OpenBSD[109] (486)
- RedHat[110] (14,717)
- Slackware[111] (941)
- Solaris[112] (1,611)
- SUSE[113] (1,444)
- Ubuntu[114] (9,179)
- UNIX[115] (9,343)
- UnixWare[116] (187)
- Windows[117] (6,612)
- Other[118]
- Services
- Security Services[129]
- Hosting By
- Rokasec[130]
Read more https://packetstormsecurity.com/files/176260/glsa-202312-01.txt


