Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 891647 (CVE-2023-24056) - <dev-util/pkgconf-1.8.1: Billion Laughs vulnerability
Summary: <dev-util/pkgconf-1.8.1: Billion Laughs vulnerability
Status: IN_PROGRESS
Alias: CVE-2023-24056
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa?]
Keywords:
Depends on: 894014
Blocks:
  Show dependency tree
 
Reported: 2023-01-22 05:21 UTC by Sam James
Modified: 2023-08-11 07:23 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-01-22 05:21:00 UTC
Fixed in 1.9.4.
Comment 1 Larry the Git Cow gentoo-dev 2023-01-22 06:04:35 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=4cac9a6d53d85038c7ca75fd95bcea2a6bdb6795

commit 4cac9a6d53d85038c7ca75fd95bcea2a6bdb6795
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-01-22 05:29:50 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-01-22 05:29:50 +0000

    dev-util/pkgconf: add 1.9.4
    
    Bug: https://bugs.gentoo.org/891647
    Signed-off-by: Sam James <sam@gentoo.org>

 dev-util/pkgconf/Manifest             |  1 +
 dev-util/pkgconf/pkgconf-1.9.4.ebuild | 70 +++++++++++++++++++++++++++++++++++
 2 files changed, 71 insertions(+)
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-01-22 08:51:44 UTC
1.9.x is still a testing release so unkeyworded. Was going to backport but doesn't apply cleanly and then saw https://social.treehouse.systems/@ariadne/109731371713946455, so waiting.
Comment 3 Larry the Git Cow gentoo-dev 2023-01-23 02:40:09 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d30761d3c18593bbee87fd2f56fad7e5893042d0

commit d30761d3c18593bbee87fd2f56fad7e5893042d0
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-01-23 02:38:45 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-01-23 02:38:45 +0000

    dev-util/pkgconf: drop 1.9.3
    
    Bug: https://bugs.gentoo.org/891647
    Signed-off-by: Sam James <sam@gentoo.org>

 dev-util/pkgconf/Manifest             |  1 -
 dev-util/pkgconf/pkgconf-1.9.3.ebuild | 70 -----------------------------------
 2 files changed, 71 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=a5c752c651b9660cc1a8a8a8726171158484b9ce

commit a5c752c651b9660cc1a8a8a8726171158484b9ce
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-01-23 02:38:31 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-01-23 02:38:31 +0000

    dev-util/pkgconf: add 1.8.1
    
    Bug: https://bugs.gentoo.org/891647
    Signed-off-by: Sam James <sam@gentoo.org>

 dev-util/pkgconf/Manifest             |  1 +
 dev-util/pkgconf/pkgconf-1.8.1.ebuild | 73 +++++++++++++++++++++++++++++++++++
 2 files changed, 74 insertions(+)
Comment 4 Larry the Git Cow gentoo-dev 2023-05-03 07:13:43 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=06302d35627e371299f53ccecd62d86e3131f3bb

commit 06302d35627e371299f53ccecd62d86e3131f3bb
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-05-03 07:13:28 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-05-03 07:13:28 +0000

    dev-util/pkgconf: drop 1.8.0-r1
    
    Bug: https://bugs.gentoo.org/891647
    Signed-off-by: Sam James <sam@gentoo.org>

 dev-util/pkgconf/Manifest                |  1 -
 dev-util/pkgconf/pkgconf-1.8.0-r1.ebuild | 74 --------------------------------
 2 files changed, 75 deletions(-)