tqdm is a smart progress meter.
+A vulnerablility was discovered in tqdm._version that could allow a + malicious git log within the current working directory. +
+A remote attacker could execute arbitrary commands by enticing a user to + clone a crafted repo. +
+There is no known workaround at this time.
+All tqdm users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=dev-python/tqdm-4.23.3"
+
+
+ Passenger runs and manages your Ruby, Node.js, and Python apps.
+Multiple vulnerabilities have been discovered in Passenger. Please + review the CVE identifiers referenced below for details. +
+A remote attacker could escalate privileges, execute arbitrary code, + cause a Denial of Service condition, or obtain sensitive information. +
+There is no known workaround at this time.
+All Passenger users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=www-apache/passenger-5.3.2"
+
+ ZNC is an advanced IRC bouncer.
+Multiple vulnerabilities have been discovered in ZNC. Please review the + CVE identifiers referenced below for details. +
+A remote attacker could read arbitary files and esclate privileges.
+There is no known workaround at this time.
+All ZNC users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=net-irc/znc-1.7.1"
+
+
+ A command line tool and library for transferring data with URLs.
+ +A heap-based buffer overflow was discovered in cURL’s + Curl_smtp_escape_eob() function. +
+An attacker could cause a Denial of Service condition or execute + arbitrary code via SMTP connections. +
+There is no known workaround at this time.
+All cURL users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=net-misc/curl-7.61.0"
+
+
+