Gentoo Security Advisory GLSA 200801-14 (blam)

Summary
The remote host is missing updates announced in advisory GLSA 200801-14.
Solution
All Blam users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose '>=net-news/blam-1.8.4' http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200801-14 http://bugs.gentoo.org/show_bug.cgi?id=199841
Insight
Blam doesn't properly handle environment variables, potentially allowing a local attacker to execute arbitrary code.