Summary: | <dev-haskell/xml-conduit-1.9.1.1: infinite loop via crafted xml | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | CONFIRMED --- | ||
Severity: | minor | CC: | haskell |
Priority: | Normal | Keywords: | PullRequest |
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://vuldb.com/?id.216204 | ||
See Also: | https://github.com/gentoo/gentoo/pull/36358 | ||
Whiteboard: | B4 [glsa?] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
![]() ![]() ![]() ![]() I brought this up in the -haskell channel regarding the PR and they said this only affects xml-conduit. Upstream just produces multiple packages from one repository so the tags for those made their way onto the commit. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=579f6b8babb24f03b82884a523a0f7c0fe4b8e9b commit 579f6b8babb24f03b82884a523a0f7c0fe4b8e9b Author: Christopher Fore <csfore@posteo.net> AuthorDate: 2024-04-22 16:22:08 +0000 Commit: Mark Wright <gienah@gentoo.org> CommitDate: 2025-05-21 10:10:14 +0000 dev-haskell/html-conduit: add 1.3.2.2 - Fix trivial QA warning - Empty IUSE Bug: https://bugs.gentoo.org/887065 Closes: https://github.com/gentoo/gentoo/pull/36358 Signed-off-by: Christopher Fore <csfore@posteo.net> Signed-off-by: Mark Wright <gienah@gentoo.org> dev-haskell/html-conduit/Manifest | 1 + .../html-conduit/html-conduit-1.3.2.2.ebuild | 32 ++++++++++++++++++++++ 2 files changed, 33 insertions(+) |