From ${URL} : It was reported [1] that when processing a crafted diff patch will loop infinitely, which can lead to resourse consumption and local denial of service. [1]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776271 @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Patch introduced by both Debian and RedHat. Maintainers, please advise.
This is was fixed by upstream in v2.7.4. Tested via https://bugs.debian.org/cgi-bin/bugreport.cgi?att=1;bug=776271;filename=loop2.patch.gz;msg=5 @ Maintainer(s): Please cleanup sys-devel/patch and drop at least =sys-devel/patch-2.7.3.
commit e00febb6b1e65871c8a4147f96338ae2eb0312c5 Author: Lars Wendler <polynomial-c@gentoo.org> Date: Thu Dec 1 22:59:10 2016 sys-devel/patch: Security cleanup (bug #538658). Package-Manager: portage-2.3.2
New GLSA created.
This issue was resolved and addressed in GLSA 201612-12 at https://security.gentoo.org/glsa/201612-12 by GLSA coordinator Aaron Bauman (b-man).