VDB
GCVE-VVD-MAGEIA-2023-77
GCVE-VVD-MAGEIA-2023-77
Advisory Published
In pkgconf through 1.9.3, variable duplication can cause unbounded string
expansion due to incorrect checks in
libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing
a few hundred bytes can expand to one billion bytes. (CVE-2023-24056)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | fsarchiver | 0 (affected), 0.8.7-1.mga9 (unaffected) | — |
| Mageia | qt-fsarchiver | 0 (affected), 0.8.6.7-4.1.mga9 (unaffected) | — |
| Mageia | qt-fsarchiver-terminal | 0 (affected), 0.8.6.7-1.1.mga9 (unaffected) | — |
| Mageia | pkgconf | 0 (affected), 1.7.3-2.1.mga8 (unaffected), 0 (affected), 1.7.3-2.1.mga8 (unaffected) | — |
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.