From ${URL} : I'd like to request a CVE identifier for an untrusted code execution problem in Chicken Scheme: The interpreter loads a file called ".csirc" from the current directory on startup, without checking whether it can be trusted. Versions 4.8.2 after c6750af99ada7fa4815ee834e4e705bcfac9c137 are unaffected, as will 4.8.3 and later. The first stable release to include a fix will be 4.9.0. For the upstream advisory info see http://lists.nongnu.org/archive/html/chicken-announce/2013-03/msg00002.html and (important!) the errata: http://lists.nongnu.org/archive/html/chicken-announce/2013-03/msg00003.html
+*chicken-4.8.0.3-r1 (08 Jul 2013) + + 08 Jul 2013; Michael Weber <xmw@gentoo.org> +chicken-4.8.0.3-r1.ebuild, + +files/chicken-4.8.0.3-CVE-2013-1874.patch, + +files/chicken-4.8.0.3-CVE-2013-2024.patch, + +files/chicken-4.8.0.3-CVE-2013-2075_1.patch, + +files/chicken-4.8.0.3-CVE-2013-2075_2.patch: + Revbump to include security patches (bugs 462458, 469392, 467966) +
GLSA vote: no. @maintainer: if this affects other versions of chicken, please clean them.
GLSA vote: no. Waiting for cleanup
Maintainer timeout. Cleaned up, closing.