A vulnerability was found in irregex which is bundled as a part of chicken. Parsing a maliciously crafted regular expression could cause resource exhaustion resulting in a Denial of Service. References: http://seclists.org/oss-sec/2016/q4/681 Upstream patch: https://github.com/ashinn/irregex/commit/a16ffc86eca15fca9e40607d41de3cea9cf868f1
Created chicken tracking bugs for this issue: Affects: fedora-all [bug 1413993] Affects: epel-all [bug 1413994]
This has been fixed for a while.