MGASA-2023-0077

Source
https://advisories.mageia.org/MGASA-2023-0077.html
Import Source
https://advisories.mageia.org/MGASA-2023-0077.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2023-0077
Related
Published
2023-03-01T21:14:31Z
Modified
2023-03-01T20:09:34Z
Summary
Updated pkgconf packages fix security vulnerability
Details

In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconftupleparse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes. (CVE-2023-24056)

References
Credits

Affected packages

Mageia:8 / pkgconf

Package

Name
pkgconf
Purl
pkg:rpm/mageia/pkgconf?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.3-2.1.mga8

Ecosystem specific

{
    "section": "core"
}