Cairo is a 2D vector graphics library with cross-device output support.
+Multiple vulnerabilities have been discovered in Cairo. Please review + the CVE identifiers referenced below for details. +
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Cairo users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=x11-libs/cairo-1.16.0-r2"
+
+ An Open Source implementation of the iCalendar protocols and protocol + data units. +
+Multiple vulnerabilities have been discovered in Libical. Please review + the referenced CVE identifiers for details. +
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Libical users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=dev-libs/libical-3.0.0"
+
+ Unbound is a validating, recursive, and caching DNS resolver.
+Multiple vulnerabilities have been discovered in Unbound. Please review + the referenced bugs for details. +
+Please review the referenced bugs for details.
+There is no known workaround at this time.
+All Unbound users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=net-dns/unbound-1.8.3"
+
+ Poppler is a PDF rendering library based on the xpdf-3.0 code base.
+Multiple vulnerabilities have been discovered in Poppler. Please review + the CVE identifiers referenced below for details. +
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All Poppler users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-text/poppler-0.70.0"
+
+ A network backup and restore program.
+It was discovered that Gentoo’s BURP ebuild does not properly set + permissions or place the pid file in a safe directory. Additionally, the + first set of patches did not completely address this. As such, a + revision has been made available that addresses all concerns of the + initial report. +
+A local attacker could escalate privileges.
+Users should ensure the proper permissions are set as discussed in the + referenced bugs. +
+All BURP users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-backup/burp-2.1.32-r1"
+
+ A free and open source software scalable network filesystem.
+Multiple vulnerabilities have been discovered in GlusterFS. Please + review the referenced CVE identifiers for details. +
+Please review the referenced CVE identifiers for details.
+There is no known workaround at this time.
+All GlusterFS users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=sys-cluster/glusterfs-4.1.8"
+
+ Mozilla Thunderbird is a popular open-source email client from the + Mozilla project. + Mozilla Firefox is a popular open-source web browser from the Mozilla + Project. +
+Multiple vulnerabilities have been discovered in Mozilla Thunderbird and + Firefox. Please review the referenced Mozilla Foundation Security + Advisories and CVE identifiers below for details. +
+Please review the referenced Mozilla Foundation Security Advisories and + CVE identifiers below for details. +
+There is no known workaround at this time.
+All Thunderbird users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=mail-client/thunderbird-60.6.1"
+
+
+ All Thunderbird bin users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose
+ ">=mail-client/thunderbird-bin-60.6.1"
+
+
+ All Firefox users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/firefox-60.6.1"
+
+
+ All Firefox bin users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-client/firefox-bin-60.6.1"
+
+ Subversion is a version control system intended to eventually replace + CVS. Like CVS, it has an optional client-server architecture (where the + server can be an Apache server running mod_svn, or an ssh program as in + CVS’s :ext: method). In addition to supporting the features found in + CVS, Subversion also provides support for moving and copying files and + directories. +
+A vulnerability was discovered in Subversion’s mod_dav_svn, that could + lead to a Denial of Service Condition. +
+An attacker could cause a possible enial of Service condition.
+There is no known workaround at this time.
+All Subversion users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=dev-vcs/subversion-1.10.4"
+
+