bison
Version: 3.8.2General-purpose parser generator in the yacc tradition
What is "bison"?
General-purpose parser generator in the yacc tradition
How to use this package
Quick install
Installs the package into the current environment for this session. Use --build or --runtime to persist it as a build-time or runtime dependency.
min add bisonDeclare as a task dependency in minimal.toml
Listing the package under tasks.<name>.packages makes it available inside that task’s sandbox.
[tasks.dev]
packages = ["bison"]Build-time vs runtime
Choose build-time for tools needed during compilation, runtime for dynamic libraries loaded at runtime.
min add --build bison
min add --runtime bisonDependencies (7)
Dependency changes
Loading diff…
Could not load the dependency diff for one of the selected versions. Try again.
No dependency changes
The two selected versions have identical direct dependencies.
| Name | Version | Kind |
|---|
Dependants (12)
| Name | Version |
|---|---|
| glibcCVE:2 | 2.44 |
| graphviz | 15.1.1 |
| iproute2 | 7.1.0 |
| libkrunfw | 5.5.0 |
| libxkbcommon | 1.13.2 |
| maude | 3.5.1 |
| mesa | 26.2.0 |
| ngspice | 46 |
| postgres | 18.6 |
| tmux | 3.7 |
| virtio-linux | 6.12.105 |
| virtio-linux-detonation | 6.18.44 |
- Lines:+1Deps:7Released:
- Lines:+4 / -2Deps:7(+2 / -1)Released:
- Lines:-1Deps:6Released:
- Lines:+4 / -1Deps:6Released:
- Lines:+4 / -1Deps:6Released:
- Lines:+2 / -2Deps:6Released:
- Lines:+1 / -1Deps:6(+1 / -1)Released:
- Lines:+2 / -2Deps:6Released:
- Lines:+1 / -1Deps:6Released:
- Lines:+1 / -1Deps:6Released:
- Lines:+1 / -1Deps:6Released:
- Lines:+1 / -1Deps:6Released:
- Lines:+1 / -1Deps:6Released:
- Lines:+1 / -1Deps:6Released:
- Lines:+8 / -1Deps:6Released:
- Lines:+6 / -1Deps:6Released:
- Lines:+15 / -5Deps:6Released:
- Lines:+3Deps:6Released:
- Lines:+2Deps:6Released:
- Lines:+1 / -1Deps:6Released:
- Lines:+6 / -2Deps:6Released:
- Lines:+62Deps:6(+6)Released:
Showing 4 advisories, 2 of which are transitive via bison's dependencies
No advisories match the current filters.
| Critical (0) | ||||||
| Status | IDs | Package | Severity | |||
|---|---|---|---|---|---|---|
| High (2) | ||||||
| Status | IDs | Package | Severity | |||
Under investigation | bison | High: 8.6 | ||||
SummaryGNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. Affected ranges3.8.2 CVSS vectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H | ||||||
Under investigation | glibc | High: 7.3 | ||||
SummaryThe deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records. ViaAffected ranges2.42 – 2.44 CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L | ||||||
| Medium (2) | ||||||
| Status | IDs | Package | Severity | |||
Under investigation | bison | Medium: 6.3 | ||||
SummaryGNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this behavior allows directing generated files to arbitrary writable locations on the filesystem, potentially overwriting existing files accessible to the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 8d101c19d4d9aaedf83a448c925513742d4efcf0. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. Affected ranges3.8.2 CVSS vectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N | ||||||
Under investigation | glibc | Medium: 6.5 | ||||
SummaryThe deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions. ViaAffected ranges2.42 – 2.44 CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L | ||||||
| Low (0) | ||||||
| Status | IDs | Package | Severity | |||
| Unknown (0) | ||||||
| Status | IDs | Package | Severity | |||
43 components
No components match your filter.
| Packages | Version |
|---|---|
| bisonROOT | 3.8.2 |
| acl | 2.4.0 |
| attr | 2.6.0 |
| bash | 5.3 |
| bash-bootstrap | 5.3 |
| binutils | 2.47 |
| bzip2 | 1.0.8 |
| coreutils | 9.11 |
| diffutils | 3.12 |
| expat | 2.8.3 |
| file | 5.48 |
| findutils | 4.11.0 |
| flex | 2.6.4 |
| gawk | 5.4.1 |
| gawk-bootstrap | 5.4.1 |
| gcc | 15.2.0 |
| gdbm | 1.26 |
| glibc | 2.44 |
| gmp | 6.3.0 |
| grep | 3.12 |
| gzip | 1.14 |
| libcap | 2.78 |
| libffi | 3.8.0 |
| linux_headers | 6.12.43 |
| lz4 | 1.10.0 |
| m4 | 1.4.21 |
| make | 4.4.1 |
| mpc | 1.4.1 |
| mpfr | 4.2.2 |
| ncurses | 6.6 |
| openssl | 3.6.3 |
| pcre2 | 10.47 |
| perl | 5.44.0 |
| pkgconf | 3.0.5 |
| python | 3.14.7 |
| readline | 8.3 |
| sed | 4.10 |
| sqlite | 3.53.4 |
| tar | 1.35 |
| util-linux | 2.42.3 |
| xz | 5.8.3 |
| zlib | 1.3.2 |
| zstd | 1.5.7 |