Summary: | <dev-haskell/xml-conduit-1.9.1.1: infinite loop via crafted xml | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | CONFIRMED --- | ||
Severity: | minor | CC: | haskell |
Priority: | Normal | Keywords: | PullRequest |
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://vuldb.com/?id.216204 | ||
See Also: | https://github.com/gentoo/gentoo/pull/36358 | ||
Whiteboard: | B4 [glsa?] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
2022-12-18 22:06:45 UTC
I brought this up in the -haskell channel regarding the PR and they said this only affects xml-conduit. Upstream just produces multiple packages from one repository so the tags for those made their way onto the commit. |