CVE-2023-24056 Information
Jan 23, 2023
cve
Description
In pkgconf through 1.9.3 variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example a .pc file containing a few hundred bytes can expand to one billion bytes.
Reference
https://gitea.treehouse.systems/ariadne/pkgconf/commit/628b2b2bafa5d3a2017193ddf375093e70666059 https://github.com/pkgconf/pkgconf/tags https://nullprogram.com/blog/2023/01/18/
Share on: