Summary: | games-util/xgamer: Package uses dev-perl/XML-Twig and makes no clear statement regarding handling of external entities (CVE-2016-9180) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Thomas Deutschmann (RETIRED) <whissi> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED WONTFIX | ||
Severity: | normal | CC: | games |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B3 [upstream?] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | |||
Bug Blocks: | 600818 |
Description
Thomas Deutschmann (RETIRED)
![]() Tested on 9/20/2017 --- developer / # grep -Fr 'use XML' xgamer xgamer/bin/xgamer:use XML::Twig; xgamer/bin/xgamer: my $twig = XML::Twig::Elt->new($tag); xgamer/bin/xgamer: my $twig = XML::Twig->new( xgamer/bin/xgamer: # Return XML as string xgamer/Build.PL: 'XML::Twig' => 0 Daj Uan (jmbailey) Gentoo Security Padawan Red Hat and upstream wontfix. No concerns with any other major vulnerabilities. |