CouchDB: Multiple vulnerabilities Multiple vulnerabilities have been found in CouchDB, the worst of which could lead to the remote execution of arbitrary shell commands. couchdb 2017-11-19 2017-11-19 637516 remote 1.7.1 1.7.1

Apache CouchDB is a distributed, fault-tolerant and schema-free document-oriented database.

Multiple vulnerabilities have been discovered in CouchDB. Please review the CVE identifiers referenced below for details.

A remote attacker could execute arbitrary shell commands or escalate privileges.

There is no known workaround at this time.

All CouchDB users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-db/couchdb-1.7.1"
CVE-2017-12635 CVE-2017-12636 jmbailey jmbailey