Multiple vulnerabilities have been discovered in libgit2, the worst of which could lead to arbitrary code execution.
Package | dev-libs/libgit2 on all architectures |
---|---|
Affected versions | < 1.7.2 |
Unaffected versions | >= 1.7.2 |
libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API, allowing you to write native speed custom Git applications in any language that supports C bindings.
Multiple vulnerabilities have been discovered in libgit2. Please review the CVE identifiers referenced below for details.
Please review the referenced CVE identifiers for details.
There is no known workaround at this time.
All libgit2 users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/libgit2-1.7.2"