GNU Wget is a free software package for retrieving files using HTTP, + HTTPS and FTP, the most widely-used Internet protocols. +
+A vulnerability was discovered in GNU Wget’s resp_new function which + does not validate \r\n sequences in continuation lines. +
+A remote attacker could inject arbitrary cookie entry requests.
+There is no known workaround at this time.
+All GNU Wget users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=net-misc/wget-1.19.5"
+
+ The Adobe Flash Player is a renderer for the SWF file format, which is + commonly used to provide interactive websites. +
+Multiple vulnerabilities have been discovered in Adobe Flash Player. + Please review the CVE identifiers referenced below for details. +
+A remote attacker could possibly execute arbitrary code with the + privileges of the process or obtain sensitive information. +
+There is no known workaround at this time.
+All Adobe Flash Player users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose
+ ">=www-plugins/adobe-flash-30.0.0.113"
+
+ A network backup and restore program.
+It was discovered that Gentoo’s BURP ebuild does not properly set + permissions or place the pid file in a safe directory. +
+A local attacker could escalate privileges.
+Users should ensure the proper permissions are set as discussed in the + referenced bugs. +
+All BURP users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=app-backup/burp-2.1.32"
+
+ Quassel is a Qt4/KDE4 IRC client suppporting a remote daemon for 24/7 + connectivity. +
+ +Multiple vulnerabilities have been discovered in Quassel. Please review + the CVE identifiers referenced below for details. +
+A remote attacker could cause arbitrary code execution or a Denial of + Service condition. +
+ +There is no known workaround at this time.
+All Quassel users should upgrade to the latest version:
+ +
+ # emerge --sync
+ # emerge --ask --oneshot --verbose ">=net-irc/quassel-0.12.5"
+
+