Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 37: FEDORA-2022-dc6d6d9d6c Critical: cmark-gfm DoS

fedora
Calendar Grey November 10, 2022
Dist Fedora Esm H88
The GHC cmark-gfm package upgrade for Fedora 37 mitigates Denial of Service vulnerabilities linked to CVE-2022-39209 while also improving Markdown formatting capabilities.
updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209

Summary

This package provides Haskell bindings for , the reference parser for , a fully specified variant of Markdown. It includes sources

for libcmark-gfm (0.29.0.gfm.6) and does not require prior installation of the

C library.

updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209

* Wed Oct 26 2022 Jens Petersen - 0.2.5-1

- 0.2.4 updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209

https://github.com/github/cmark-gfm/security/advisories/GHSA-cgh3-p57x-9q7q

- 0.2.5 includes support for footnotes

- https://hackage.haskell.org/package/cmark-gfm-0.2.5/changelog

[ 1 ] Bug #2128044 - CVE-2022-39209 cmark-gfm: Unbounded resource exhaustion may lead to denial of service

https://bugzilla.redhat.com/show_bug.cgi?id=2128044

su -c 'dnf upgrade --advisory FEDORA-2022-dc6d6d9d6c' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 37
Version: 0.2.5
Release: 1.fc37
Summary: Fast, accurate GitHub Flavored Markdown parser and renderer

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here