GLSA-200805-14 : Common Data Format library: User-assisted execution of arbitrary code
High Nessus Plugin ID 32351
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-200805-14 (Common Data Format library: User-assisted execution of arbitrary code)
Alfredo Ortega (Core Security Technologies) reported a boundary error within the Read32s_64() function when processing CDF files.
A remote attacker could entice a user to open a specially crafted CDF file, possibly resulting in the remote execution of arbitrary code with the privileges of the user running the application.
There is no known workaround at this time.
SolutionAll Common Data Format library users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=sci-libs/cdf-3.2.1'