Gentoo: GLSA-202409-21: Hunspell: Security Advisory Updates
Summary
Malicious input to the hunspell spell checker could result in an
application crash or other unspecified behavior.
Resolution
All Hunspell users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-text/hunspell-1.7.1"
References
Availability
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202409-21
Concerns
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.
Synopsis
Multiple vulnerabilities have been discovered in Hunspell, the worst of
which could lead to arbitrary code execution.
Background
Hunspell is the spell checker of LibreOffice, OpenOffice.org, Mozilla
Firefox & Thunderbird, Google Chrome.
Affected Packages
Package Vulnerable Unaffected
----------------- ------------ ------------
app-text/hunspell < 1.7.1 >= 1.7.1
Impact
Malicious input to the hunspell spell checker could result in an
application crash or other unspecified behavior.
Workaround
There is no known workaround at this time.