Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia 8 MGASA-2023-0181 Moderate: cmark Denial Of Service Threat

mageia
Calendar Grey May 21, 2023
Dist Mageia Esm H88
Urgent update released for cmark in Mageia tackles denial of service vulnerabilities and parsing problems recognized in CVEs.
cmark incorrectly handled certain inputs

Summary

cmark incorrectly handled certain inputs. Fixes quadratic complexity in handle_close_bracket "![[]()" which may lead to a denial of service (CVE-2023-22486). Noting that this also fixes a quadratic parsing issue with repeated that was not in a released product but which was assigned a CVE (CVE-2023-22484).

References

- https://bugs.mageia.org/show_bug.cgi?id=31885

- https://lists.suse.com/pipermail/sle-security-updates/2023-May/014722.html

- https://github.com/commonmark/cmark/releases/tag/0.30.3

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22484

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22486

Resolution

SRPMS

- 8/core/cmark-0.30.3-1.mga8

Publication date: 21 May 2023
URL: https://advisories.mageia.org/MGASA-2023-0181.html
Type: security
CVE: CVE-2023-22484, CVE-2023-22486

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here