--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-6ad6b9f417
2024-03-31 01:53:51.907786
--------------------------------------------------------------------------------

Name        : pandoc
Product     : Fedora 38
Version     : 2.19.2
Release     : 22.fc38
URL         : https://hackage.haskell.org/package/pandoc
Summary     : Conversion between markup formats
Description :
Pandoc is a Haskell library for converting from one markup format to another,
and a command-line tool that uses this library. The formats it can handle
include

- light markup formats (many variants of Markdown, reStructuredText, AsciiDoc,
Org-mode, Muse, Textile, txt2tags) - HTML formats (HTML 4 and 5) - Ebook
formats (EPUB v2 and v3, FB2) - Documentation formats (GNU TexInfo, Haddock) -
Roff formats (man, ms) - TeX formats (LaTeX, ConTeXt) - XML formats (DocBook 4
and 5, JATS, TEI Simple, OpenDocument) - Outline formats (OPML) - Bibliography
formats (BibTeX, BibLaTeX, CSL JSON, CSL YAML, RIS) - Word processor formats
(Docx, RTF, ODT) - Interactive notebook formats (Jupyter notebook ipynb) - Page
layout formats (InDesign ICML) - Wiki markup formats (MediaWiki, DokuWiki,
TikiWiki, TWiki, Vimwiki, XWiki, ZimWiki, Jira wiki, Creole) - Slide show
formats (LaTeX Beamer, PowerPoint, Slidy, reveal.js, Slideous, S5, DZSlides) -
Data formats (CSV and TSV tables) - PDF (via external programs such as pdflatex
or wkhtmltopdf)

Pandoc can convert mathematical content in documents between TeX, MathML, Word
equations, roff eqn, and plain text. It includes a powerful system for
automatic citations and bibliographies, and it can be customized extensively
using templates, filters, and custom readers and writers written in Lua.

For pdf output please also install pandoc-pdf or weasyprint.

--------------------------------------------------------------------------------
Update Information:

Security fix for CVE-2023-35936 and CVE-2023-38745
pandoc: backport fixes for CVE-2023-35936 and CVE-2023-38745
base64 now packaged in Fedora
--------------------------------------------------------------------------------
ChangeLog:

* Thu Mar 21 2024 Jens Petersen  - 2.19.2-22
- backport fixes for CVE-2023-35936 and CVE-2023-38745
- base64 is now packaged in fedora
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2163472 - Review Request: ghc-base64 - A modern RFC 4648-compliant Base64 library
        https://bugzilla.redhat.com/show_bug.cgi?id=2163472
  [ 2 ] Bug #2220873 - TRIAGE pandoc: TRIAGE_CVE-2023-35936 pandoc: allows attacker to create or overwrite arbitrary files on the system [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2220873
  [ 3 ] Bug #2227034 - CVE-2023-38745 pandoc: allows attacker to create or overwrite arbitrary files on the system [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2227034
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-6ad6b9f417' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
--
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/
Do not reply to spam, report it: https://pagure.io/login/

Fedora 38: pandoc 2024-6ad6b9f417

March 31, 2024
Security fix for CVE-2023-35936 and CVE-2023-38745 pandoc: backport fixes for CVE-2023-35936 and CVE-2023-38745 base64 now packaged in Fedora

Summary

Pandoc is a Haskell library for converting from one markup format to another,

and a command-line tool that uses this library. The formats it can handle

include

- light markup formats (many variants of Markdown, reStructuredText, AsciiDoc,

Org-mode, Muse, Textile, txt2tags) - HTML formats (HTML 4 and 5) - Ebook

formats (EPUB v2 and v3, FB2) - Documentation formats (GNU TexInfo, Haddock) -

Roff formats (man, ms) - TeX formats (LaTeX, ConTeXt) - XML formats (DocBook 4

and 5, JATS, TEI Simple, OpenDocument) - Outline formats (OPML) - Bibliography

formats (BibTeX, BibLaTeX, CSL JSON, CSL YAML, RIS) - Word processor formats

(Docx, RTF, ODT) - Interactive notebook formats (Jupyter notebook ipynb) - Page

layout formats (InDesign ICML) - Wiki markup formats (MediaWiki, DokuWiki,

TikiWiki, TWiki, Vimwiki, XWiki, ZimWiki, Jira wiki, Creole) - Slide show

formats (LaTeX Beamer, PowerPoint, Slidy, reveal.js, Slideous, S5, DZSlides) -

Data formats (CSV and TSV tables) - PDF (via external programs such as pdflatex

or wkhtmltopdf)

Pandoc can convert mathematical content in documents between TeX, MathML, Word

equations, roff eqn, and plain text. It includes a powerful system for

automatic citations and bibliographies, and it can be customized extensively

using templates, filters, and custom readers and writers written in Lua.

For pdf output please also install pandoc-pdf or weasyprint.

Update Information:

Security fix for CVE-2023-35936 and CVE-2023-38745 pandoc: backport fixes for CVE-2023-35936 and CVE-2023-38745 base64 now packaged in Fedora

Change Log

* Thu Mar 21 2024 Jens Petersen - 2.19.2-22 - backport fixes for CVE-2023-35936 and CVE-2023-38745 - base64 is now packaged in fedora

References

[ 1 ] Bug #2163472 - Review Request: ghc-base64 - A modern RFC 4648-compliant Base64 library https://bugzilla.redhat.com/show_bug.cgi?id=2163472 [ 2 ] Bug #2220873 - TRIAGE pandoc: TRIAGE_CVE-2023-35936 pandoc: allows attacker to create or overwrite arbitrary files on the system [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2220873 [ 3 ] Bug #2227034 - CVE-2023-38745 pandoc: allows attacker to create or overwrite arbitrary files on the system [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2227034

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-6ad6b9f417' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
Name : pandoc
Product : Fedora 38
Version : 2.19.2
Release : 22.fc38
URL : https://hackage.haskell.org/package/pandoc
Summary : Conversion between markup formats

Related News