+ RTMPDump: Multiple vulnerabilities
+ Multiple vulnerabilities have been found in RTMPDump, the worst of
+ which could lead to arbitrary code execution.
+
+ rtmpdump
+ 2017-02-06
+ 2017-02-06: 1
+ 570242
+ remote
+
+
+ 2.4_p20161210
+ 2.4_p20161210
+
+
+
+ RTMPDump is an RTMP client intended to stream audio or video flash
+ content
+
+
+
+ Multiple vulnerabilities have been discovered in RTMPDump.
+
+ The following is a list of vulnerabilities fixed:
+
+
+ - Additional decode input size checks
+ - Ignore zero-length packets
+ - Potential integer overflow in RTMPPacket_Alloc().
+ - Obsolete RTMPPacket_Free() call left over from original C++ to C
+ rewrite
+
+ - AMFProp_GetObject must make sure the prop is actually an object
+
+
+
+
+ A remote attacker could entice a user to open a specially crafted media
+ flash file using RTMPDump. This could possibly result in the execution of
+ arbitrary code with the privileges of the process or a Denial of Service
+ condition.
+
+
+
+ There is no known workaround at this time.
+
+
+ All RTMPDump users should upgrade to the latest version:
+
+
+ # emerge --sync
+ # emerge --ask --oneshot --verbose
+ ">=media-video/rtmpdump-2.4_p20161210"
+
+
+
+ OSS ML
+ CVE Request
+
+
+ BlueKnight
+ BlueKnight
+
diff --git a/metadata/glsa/timestamp.chk b/metadata/glsa/timestamp.chk
index 327a1bf09820..a395af073a42 100644
--- a/metadata/glsa/timestamp.chk
+++ b/metadata/glsa/timestamp.chk
@@ -1 +1 @@
-Sun, 05 Feb 2017 16:13:22 +0000
+Mon, 06 Feb 2017 08:43:32 +0000
diff --git a/metadata/md5-cache/app-arch/createrepo-0.10.4 b/metadata/md5-cache/app-arch/createrepo-0.10.4
index d8d53ea23731..05fe7fc4a0a1 100644
--- a/metadata/md5-cache/app-arch/createrepo-0.10.4
+++ b/metadata/md5-cache/app-arch/createrepo-0.10.4
@@ -1,7 +1,7 @@
-DEFINED_PHASES=compile install prepare setup
+DEFINED_PHASES=install setup
DEPEND=>=dev-lang/python-2.7.5-r2:2.7[xml] >=dev-lang/python-exec-2:=[python_targets_python2_7(-)?,-python_single_target_jython2_7(-),-python_single_target_pypy(-),-python_single_target_pypy3(-),-python_single_target_python3_4(-),-python_single_target_python3_5(-),-python_single_target_python3_6(-),python_single_target_python2_7(+)]
DESCRIPTION=Creates a common rpm-metadata repository
-EAPI=5
+EAPI=6
HOMEPAGE=http://createrepo.baseurl.org/
IUSE=python_targets_python2_7
KEYWORDS=~amd64 ~x86
@@ -9,6 +9,6 @@ LICENSE=GPL-2
RDEPEND=>=dev-python/urlgrabber-2.9.0[python_targets_python2_7(-)?,-python_single_target_jython2_7(-),-python_single_target_pypy(-),-python_single_target_pypy3(-),-python_single_target_python3_4(-),-python_single_target_python3_5(-),-python_single_target_python3_6(-),python_single_target_python2_7(+)] >=app-arch/rpm-4.1.1[python,python_targets_python2_7(-)?,-python_single_target_jython2_7(-),-python_single_target_pypy(-),-python_single_target_pypy3(-),-python_single_target_python3_4(-),-python_single_target_python3_5(-),-python_single_target_python3_6(-),python_single_target_python2_7(+)] dev-libs/libxml2[python,python_targets_python2_7(-)?,-python_single_target_jython2_7(-),-python_single_target_pypy(-),-python_single_target_pypy3(-),-python_single_target_python3_4(-),-python_single_target_python3_5(-),-python_single_target_python3_6(-),python_single_target_python2_7(+)] >=app-arch/deltarpm-3.6_pre20110223[python,python_targets_python2_7(-)?,-python_single_target_jython2_7(-),-python_single_target_pypy(-),-python_single_target_pypy3(-),-python_single_target_python3_4(-),-python_single_target_python3_5(-),-python_single_target_python3_6(-),python_single_target_python2_7(+)] dev-python/pyliblzma[python_targets_python2_7(-)?,-python_single_target_jython2_7(-),-python_single_target_pypy(-),-python_single_target_pypy3(-),-python_single_target_python3_4(-),-python_single_target_python3_5(-),-python_single_target_python3_6(-),python_single_target_python2_7(+)] >=sys-apps/yum-3.4.3 >=dev-lang/python-2.7.5-r2:2.7[xml] >=dev-lang/python-exec-2:=[python_targets_python2_7(-)?,-python_single_target_jython2_7(-),-python_single_target_pypy(-),-python_single_target_pypy3(-),-python_single_target_python3_4(-),-python_single_target_python3_5(-),-python_single_target_python3_6(-),python_single_target_python2_7(+)]
REQUIRED_USE=python_targets_python2_7
SLOT=0
-SRC_URI=http://createrepo.baseurl.org/download/createrepo-0.10.4.tar.gz https://dev.gentoo.org/~pacho/maintainer-needed/createrepo-0.9.9-head.patch.bz2
-_eclasses_=bash-completion-r1 acf715fa09463f043fbfdc1640f3fb85 eutils ea170b525f6a38a006be05c9d9429f13 multilib 165fc17c38d1b11dac2008280dab6e80 python-single-r1 19a74c6b5c191723a997dc7e0cc6bb09 python-utils-r1 d275302cd06aedef2ba08f81f3104206 toolchain-funcs 1b1da0c45c555989dc5d832b54880783
-_md5_=1ee06f2c06d5c92c06eaa9261bdfbbd9
+SRC_URI=http://createrepo.baseurl.org/download/createrepo-0.10.4.tar.gz
+_eclasses_=bash-completion-r1 acf715fa09463f043fbfdc1640f3fb85 multilib 165fc17c38d1b11dac2008280dab6e80 python-single-r1 19a74c6b5c191723a997dc7e0cc6bb09 python-utils-r1 d275302cd06aedef2ba08f81f3104206 toolchain-funcs 1b1da0c45c555989dc5d832b54880783
+_md5_=f8d9e4a03438d7600d0e5466754def1b
diff --git a/metadata/md5-cache/app-arch/deltarpm-3.6 b/metadata/md5-cache/app-arch/deltarpm-3.6
index 3c3870f9a867..261a6018c99a 100644
--- a/metadata/md5-cache/app-arch/deltarpm-3.6
+++ b/metadata/md5-cache/app-arch/deltarpm-3.6
@@ -1,7 +1,7 @@
DEFINED_PHASES=compile install setup
DEPEND=sys-libs/zlib app-arch/xz-utils app-arch/bzip2