From ${URL} : I just received the CVE-2017-11343 assignment for an issue in CHICKEN Scheme. An attacker is able to cause O(n) lookup for hash tables by predicting the buckets in which interned symbols will end up, due to a partially incorrect fix for CVE-2012-6125 where the randomization factor was determined before initializing the PRNG with a seed state. This issue affects only the Scheme symbol table, not user-created hash tables. All CHICKEN releases up to and including 4.12.0 are affected. More info: http://lists.nongnu.org/archive/html/chicken-announce/2017-07/msg00000.html @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
I've added chicken-4.13, which fixed all CVEs: https://code.call-cc.org/releases/4.13.0/NEWS I've enabled test suite and all tests pass, so I think it's safe to stabilize chicken-4.13.0.
amd64 stable
x86 stable
~ppc/~ppc64 stable
Stable on alpha.
tree is clean. GLSA Vote: No