libav: Multiple vulnerabilities Multiple vulnerabilities have been found in libav, the worst of which may allow execution of arbitrary code. libav 2017-05-09 2017-05-09 552320 571870 600706 remote 11.8 11.8

Libav is a complete solution to record, convert and stream audio and video.

Multiple vulnerabilities have been discovered in libav. Please review the CVE identifiers referenced below for details.

A remote attacker could entice a user to open a specially crafted media file in an application linked against libav, possibly resulting in execution of arbitrary code with the privileges of the application, a Denial of Service condition or access the content of arbitrary local files.

There is no known workaround at this time.

All libav users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-video/libav-11.8"
CVE-2015-3395 CVE-2015-3417 CVE-2016-1897 CVE-2016-1898 CVE-2016-2326 CVE-2016-3062 BlueKnight whissi