pkgconf is a program which helps to configure compiler and linker flags for development frameworks. It is similar to pkg-config from freedesktop.org, providing additional functionality while also maintaining compatibility.
Security Fix(es):
In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconftupleparse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes.(CVE-2023-24056)
{
"severity": "Critical"
}{
"src": [
"pkgconf-1.7.3-2.oe1.src.rpm"
],
"x86_64": [
"pkgconf-debugsource-1.7.3-2.oe1.x86_64.rpm",
"pkgconf-1.7.3-2.oe1.x86_64.rpm",
"pkgconf-devel-1.7.3-2.oe1.x86_64.rpm",
"pkgconf-debuginfo-1.7.3-2.oe1.x86_64.rpm"
],
"aarch64": [
"pkgconf-debugsource-1.7.3-2.oe1.aarch64.rpm",
"pkgconf-devel-1.7.3-2.oe1.aarch64.rpm",
"pkgconf-1.7.3-2.oe1.aarch64.rpm",
"pkgconf-debuginfo-1.7.3-2.oe1.aarch64.rpm"
],
"noarch": [
"pkgconf-help-1.7.3-2.oe1.noarch.rpm"
]
}
{
"src": [
"pkgconf-1.7.3-2.oe1.src.rpm"
],
"x86_64": [
"pkgconf-1.7.3-2.oe1.x86_64.rpm",
"pkgconf-devel-1.7.3-2.oe1.x86_64.rpm",
"pkgconf-debugsource-1.7.3-2.oe1.x86_64.rpm",
"pkgconf-debuginfo-1.7.3-2.oe1.x86_64.rpm"
],
"aarch64": [
"pkgconf-debugsource-1.7.3-2.oe1.aarch64.rpm",
"pkgconf-devel-1.7.3-2.oe1.aarch64.rpm",
"pkgconf-1.7.3-2.oe1.aarch64.rpm",
"pkgconf-debuginfo-1.7.3-2.oe1.aarch64.rpm"
],
"noarch": [
"pkgconf-help-1.7.3-2.oe1.noarch.rpm"
]
}
{
"src": [
"pkgconf-1.8.0-3.oe2203.src.rpm",
"pkgconf-1.8.0-3.oe2203sp1.src.rpm"
],
"x86_64": [
"pkgconf-debugsource-1.8.0-3.oe2203.x86_64.rpm",
"pkgconf-1.8.0-3.oe2203.x86_64.rpm",
"pkgconf-devel-1.8.0-3.oe2203.x86_64.rpm",
"pkgconf-debuginfo-1.8.0-3.oe2203.x86_64.rpm",
"pkgconf-devel-1.8.0-3.oe2203sp1.x86_64.rpm",
"pkgconf-debuginfo-1.8.0-3.oe2203sp1.x86_64.rpm",
"pkgconf-1.8.0-3.oe2203sp1.x86_64.rpm",
"pkgconf-debugsource-1.8.0-3.oe2203sp1.x86_64.rpm"
],
"aarch64": [
"pkgconf-devel-1.8.0-3.oe2203.aarch64.rpm",
"pkgconf-debugsource-1.8.0-3.oe2203.aarch64.rpm",
"pkgconf-1.8.0-3.oe2203.aarch64.rpm",
"pkgconf-debuginfo-1.8.0-3.oe2203.aarch64.rpm",
"pkgconf-1.8.0-3.oe2203sp1.aarch64.rpm",
"pkgconf-devel-1.8.0-3.oe2203sp1.aarch64.rpm",
"pkgconf-debuginfo-1.8.0-3.oe2203sp1.aarch64.rpm",
"pkgconf-debugsource-1.8.0-3.oe2203sp1.aarch64.rpm"
],
"noarch": [
"pkgconf-help-1.8.0-3.oe2203.noarch.rpm",
"pkgconf-help-1.8.0-3.oe2203sp1.noarch.rpm"
]
}
{
"src": [
"pkgconf-1.8.0-3.oe2203sp1.src.rpm"
],
"x86_64": [
"pkgconf-devel-1.8.0-3.oe2203sp1.x86_64.rpm",
"pkgconf-debuginfo-1.8.0-3.oe2203sp1.x86_64.rpm",
"pkgconf-1.8.0-3.oe2203sp1.x86_64.rpm",
"pkgconf-debugsource-1.8.0-3.oe2203sp1.x86_64.rpm"
],
"aarch64": [
"pkgconf-1.8.0-3.oe2203sp1.aarch64.rpm",
"pkgconf-devel-1.8.0-3.oe2203sp1.aarch64.rpm",
"pkgconf-debuginfo-1.8.0-3.oe2203sp1.aarch64.rpm",
"pkgconf-debugsource-1.8.0-3.oe2203sp1.aarch64.rpm"
],
"noarch": [
"pkgconf-help-1.8.0-3.oe2203sp1.noarch.rpm"
]
}