« List of all CVEs

CVE-2023-24056

Published: 1/22/2023 Last updated: 4/2/2025 Reserved: 1/22/2023

In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5.5 Medium CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Opam packages affected (2)

conf-pkg-config vorbis

Products affected (1)

Product Vendor Version
n/a n/a Android-7.1.1

References (6)