CVE-2022-24953: The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environments and GPG versions. Please remember to file security bugs for your packages alongside stablereqs.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=786475e77ec09887be16e2fbfc09336003dd6e71 commit 786475e77ec09887be16e2fbfc09336003dd6e71 Author: Michael Orlitzky <mjo@gentoo.org> AuthorDate: 2023-07-05 20:45:02 +0000 Commit: Michael Orlitzky <mjo@gentoo.org> CommitDate: 2023-07-05 20:49:40 +0000 dev-php/PEAR-Crypt_GPG: drop 1.6.2 Bug: https://bugs.gentoo.org/833570 Signed-off-by: Michael Orlitzky <mjo@gentoo.org> dev-php/PEAR-Crypt_GPG/Manifest | 1 - dev-php/PEAR-Crypt_GPG/PEAR-Crypt_GPG-1.6.2.ebuild | 49 ------------------- .../files/fix-unit-tests-with-new-gpg.patch | 55 ---------------------- 3 files changed, 105 deletions(-)
I vote noglsa for this bug.
(In reply to Hans de Graaff from comment #2) > I vote noglsa for this bug. Feel free to do so unilaterally! ;)