From ${URL} : It was reported [1] that the OAuth implementation in librest, a helper library for RESTful services part of the GNOME project, incorrectly truncates the pointer returned by the rest_proxy_call_get_url function call, leading to an application crash, or worse. Upstream bug: https://bugzilla.gnome.org/show_bug.cgi?id=742644 Commit: https://git.gnome.org/browse/librest/commit/?id=b50ace7738ea038 [1]: https://bugzilla.redhat.com/show_bug.cgi?id=1183982 @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Thanks, fixed. +*rest-0.7.92-r2 (05 Mar 2015) + + 05 Mar 2015; Alexandre Rostovtsev <tetromino@gentoo.org> -rest-0.7.91.ebuild, + +rest-0.7.92-r2.ebuild, +files/rest-0.7.92-oauth-missing-include.patch, + +files/rest-0.7.92-tests-GError-pointers.patch, + +files/rest-0.7.92-xml-parser-missing-break.patch: + Fix potentially exploitable memory corruption (bug #542264, thanks to + Agostino Sarubbo). Punt old. Note to arch teams: you will first need to stabilize =net-libs/libsoup-gnome-2.46.0-r1 due to multilib deps.
the fixed version is in stable for some time
Like already said package is already stable. No vulnerable version left in repository. @ Security: Please vote!
GLSA Vote: No