- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202305-34
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: CGAL: Multiple Vulnerabilities
     Date: May 30, 2023
     Bugs: #774261
       ID: 202305-34

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
=======
Multiple vulnerabilities have been found in CGAL, the worst of which
could result in arbitrary code execution.

Background
=========
CGAL is a C++ library for geometric algorithms and data structures.

Affected packages
================
Package               Vulnerable    Unaffected
--------------------  ------------  ------------
sci-mathematics/cgal  < 5.4.1       >= 5.4.1

Description
==========
Multiple vulnerabilities have been discovered in CGAL. Please review the
CVE identifiers referenced below for details.

Impact
=====
Please review the referenced CVE identifiers for details.

Workaround
=========
There is no known workaround at this time.

Resolution
=========
All CGAL users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=sci-mathematics/cgal-5.4.1"

References
=========
[ 1 ] CVE-2020-28601
      https://nvd.nist.gov/vuln/detail/CVE-2020-28601
[ 2 ] CVE-2020-28602
      https://nvd.nist.gov/vuln/detail/CVE-2020-28602
[ 3 ] CVE-2020-28603
      https://nvd.nist.gov/vuln/detail/CVE-2020-28603
[ 4 ] CVE-2020-28604
      https://nvd.nist.gov/vuln/detail/CVE-2020-28604
[ 5 ] CVE-2020-28605
      https://nvd.nist.gov/vuln/detail/CVE-2020-28605
[ 6 ] CVE-2020-28606
      https://nvd.nist.gov/vuln/detail/CVE-2020-28606
[ 7 ] CVE-2020-28607
      https://nvd.nist.gov/vuln/detail/CVE-2020-28607
[ 8 ] CVE-2020-28608
      https://nvd.nist.gov/vuln/detail/CVE-2020-28608
[ 9 ] CVE-2020-28610
      https://nvd.nist.gov/vuln/detail/CVE-2020-28610
[ 10 ] CVE-2020-28611
      https://nvd.nist.gov/vuln/detail/CVE-2020-28611
[ 11 ] CVE-2020-28612
      https://nvd.nist.gov/vuln/detail/CVE-2020-28612
[ 12 ] CVE-2020-28613
      https://nvd.nist.gov/vuln/detail/CVE-2020-28613
[ 13 ] CVE-2020-28614
      https://nvd.nist.gov/vuln/detail/CVE-2020-28614
[ 14 ] CVE-2020-28615
      https://nvd.nist.gov/vuln/detail/CVE-2020-28615
[ 15 ] CVE-2020-28616
      https://nvd.nist.gov/vuln/detail/CVE-2020-28616
[ 16 ] CVE-2020-28617
      https://nvd.nist.gov/vuln/detail/CVE-2020-28617
[ 17 ] CVE-2020-28618
      https://nvd.nist.gov/vuln/detail/CVE-2020-28618
[ 18 ] CVE-2020-28619
      https://nvd.nist.gov/vuln/detail/CVE-2020-28619
[ 19 ] CVE-2020-28620
      https://nvd.nist.gov/vuln/detail/CVE-2020-28620
[ 20 ] CVE-2020-28621
      https://nvd.nist.gov/vuln/detail/CVE-2020-28621
[ 21 ] CVE-2020-28622
      https://nvd.nist.gov/vuln/detail/CVE-2020-28622
[ 22 ] CVE-2020-28623
      https://nvd.nist.gov/vuln/detail/CVE-2020-28623
[ 23 ] CVE-2020-28624
      https://nvd.nist.gov/vuln/detail/CVE-2020-28624
[ 24 ] CVE-2020-28625
      https://nvd.nist.gov/vuln/detail/CVE-2020-28625
[ 25 ] CVE-2020-28626
      https://nvd.nist.gov/vuln/detail/CVE-2020-28626
[ 26 ] CVE-2020-28627
      https://nvd.nist.gov/vuln/detail/CVE-2020-28627
[ 27 ] CVE-2020-28628
      https://nvd.nist.gov/vuln/detail/CVE-2020-28628
[ 28 ] CVE-2020-28629
      https://nvd.nist.gov/vuln/detail/CVE-2020-28629
[ 29 ] CVE-2020-28630
      https://nvd.nist.gov/vuln/detail/CVE-2020-28630
[ 30 ] CVE-2020-28631
      https://nvd.nist.gov/vuln/detail/CVE-2020-28631
[ 31 ] CVE-2020-28632
      https://nvd.nist.gov/vuln/detail/CVE-2020-28632
[ 32 ] CVE-2020-28633
      https://nvd.nist.gov/vuln/detail/CVE-2020-28633
[ 33 ] CVE-2020-28634
      https://nvd.nist.gov/vuln/detail/CVE-2020-28634
[ 34 ] CVE-2020-28635
      https://nvd.nist.gov/vuln/detail/CVE-2020-28635
[ 35 ] CVE-2020-28636
      https://nvd.nist.gov/vuln/detail/CVE-2020-28636
[ 36 ] CVE-2020-35628
      https://nvd.nist.gov/vuln/detail/CVE-2020-35628
[ 37 ] CVE-2020-35629
      https://nvd.nist.gov/vuln/detail/CVE-2020-35629
[ 38 ] CVE-2020-35630
      https://nvd.nist.gov/vuln/detail/CVE-2020-35630
[ 39 ] CVE-2020-35631
      https://nvd.nist.gov/vuln/detail/CVE-2020-35631
[ 40 ] CVE-2020-35632
      https://nvd.nist.gov/vuln/detail/CVE-2020-35632
[ 41 ] CVE-2020-35633
      https://nvd.nist.gov/vuln/detail/CVE-2020-35633
[ 42 ] CVE-2020-35634
      https://nvd.nist.gov/vuln/detail/CVE-2020-35634
[ 43 ] CVE-2020-35635
      https://nvd.nist.gov/vuln/detail/CVE-2020-35635
[ 44 ] CVE-2020-35636
      https://nvd.nist.gov/vuln/detail/CVE-2020-35636

Availability
===========
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202305-34

Concerns?
========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
======
Copyright 2023 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5/

Gentoo: GLSA-202305-34: CGAL: Multiple Vulnerabilities

Multiple vulnerabilities have been found in CGAL, the worst of which could result in arbitrary code execution.

Summary

Multiple vulnerabilities have been discovered in CGAL. Please review the CVE identifiers referenced below for details.

Resolution

All CGAL users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=sci-mathematics/cgal-5.4.1"

References

[ 1 ] CVE-2020-28601 https://nvd.nist.gov/vuln/detail/CVE-2020-28601 [ 2 ] CVE-2020-28602 https://nvd.nist.gov/vuln/detail/CVE-2020-28602 [ 3 ] CVE-2020-28603 https://nvd.nist.gov/vuln/detail/CVE-2020-28603 [ 4 ] CVE-2020-28604 https://nvd.nist.gov/vuln/detail/CVE-2020-28604 [ 5 ] CVE-2020-28605 https://nvd.nist.gov/vuln/detail/CVE-2020-28605 [ 6 ] CVE-2020-28606 https://nvd.nist.gov/vuln/detail/CVE-2020-28606 [ 7 ] CVE-2020-28607 https://nvd.nist.gov/vuln/detail/CVE-2020-28607 [ 8 ] CVE-2020-28608 https://nvd.nist.gov/vuln/detail/CVE-2020-28608 [ 9 ] CVE-2020-28610 https://nvd.nist.gov/vuln/detail/CVE-2020-28610 [ 10 ] CVE-2020-28611 https://nvd.nist.gov/vuln/detail/CVE-2020-28611 [ 11 ] CVE-2020-28612 https://nvd.nist.gov/vuln/detail/CVE-2020-28612 [ 12 ] CVE-2020-28613 https://nvd.nist.gov/vuln/detail/CVE-2020-28613 [ 13 ] CVE-2020-28614 https://nvd.nist.gov/vuln/detail/CVE-2020-28614 [ 14 ] CVE-2020-28615 https://nvd.nist.gov/vuln/detail/CVE-2020-28615 [ 15 ] CVE-2020-28616 https://nvd.nist.gov/vuln/detail/CVE-2020-28616 [ 16 ] CVE-2020-28617 https://nvd.nist.gov/vuln/detail/CVE-2020-28617 [ 17 ] CVE-2020-28618 https://nvd.nist.gov/vuln/detail/CVE-2020-28618 [ 18 ] CVE-2020-28619 https://nvd.nist.gov/vuln/detail/CVE-2020-28619 [ 19 ] CVE-2020-28620 https://nvd.nist.gov/vuln/detail/CVE-2020-28620 [ 20 ] CVE-2020-28621 https://nvd.nist.gov/vuln/detail/CVE-2020-28621 [ 21 ] CVE-2020-28622 https://nvd.nist.gov/vuln/detail/CVE-2020-28622 [ 22 ] CVE-2020-28623 https://nvd.nist.gov/vuln/detail/CVE-2020-28623 [ 23 ] CVE-2020-28624 https://nvd.nist.gov/vuln/detail/CVE-2020-28624 [ 24 ] CVE-2020-28625 https://nvd.nist.gov/vuln/detail/CVE-2020-28625 [ 25 ] CVE-2020-28626 https://nvd.nist.gov/vuln/detail/CVE-2020-28626 [ 26 ] CVE-2020-28627 https://nvd.nist.gov/vuln/detail/CVE-2020-28627 [ 27 ] CVE-2020-28628 https://nvd.nist.gov/vuln/detail/CVE-2020-28628 [ 28 ] CVE-2020-28629 https://nvd.nist.gov/vuln/detail/CVE-2020-28629 [ 29 ] CVE-2020-28630 https://nvd.nist.gov/vuln/detail/CVE-2020-28630 [ 30 ] CVE-2020-28631 https://nvd.nist.gov/vuln/detail/CVE-2020-28631 [ 31 ] CVE-2020-28632 https://nvd.nist.gov/vuln/detail/CVE-2020-28632 [ 32 ] CVE-2020-28633 https://nvd.nist.gov/vuln/detail/CVE-2020-28633 [ 33 ] CVE-2020-28634 https://nvd.nist.gov/vuln/detail/CVE-2020-28634 [ 34 ] CVE-2020-28635 https://nvd.nist.gov/vuln/detail/CVE-2020-28635 [ 35 ] CVE-2020-28636 https://nvd.nist.gov/vuln/detail/CVE-2020-28636 [ 36 ] CVE-2020-35628 https://nvd.nist.gov/vuln/detail/CVE-2020-35628 [ 37 ] CVE-2020-35629 https://nvd.nist.gov/vuln/detail/CVE-2020-35629 [ 38 ] CVE-2020-35630 https://nvd.nist.gov/vuln/detail/CVE-2020-35630 [ 39 ] CVE-2020-35631 https://nvd.nist.gov/vuln/detail/CVE-2020-35631 [ 40 ] CVE-2020-35632 https://nvd.nist.gov/vuln/detail/CVE-2020-35632 [ 41 ] CVE-2020-35633 https://nvd.nist.gov/vuln/detail/CVE-2020-35633 [ 42 ] CVE-2020-35634 https://nvd.nist.gov/vuln/detail/CVE-2020-35634 [ 43 ] CVE-2020-35635 https://nvd.nist.gov/vuln/detail/CVE-2020-35635 [ 44 ] CVE-2020-35636 https://nvd.nist.gov/vuln/detail/CVE-2020-35636

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202305-34

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity
Severity: High
Title: CGAL: Multiple Vulnerabilities
Date: May 30, 2023
Bugs: #774261
ID: 202305-34

Synopsis

Multiple vulnerabilities have been found in CGAL, the worst of which could result in arbitrary code execution.

Background

CGAL is a C++ library for geometric algorithms and data structures.

Affected Packages

Package Vulnerable Unaffected -------------------- ------------ ------------ sci-mathematics/cgal < 5.4.1 >= 5.4.1

Impact

===== Please review the referenced CVE identifiers for details.

Workaround

There is no known workaround at this time.

Related News