==========================================================================
Ubuntu Security Notice USN-6424-1
October 10, 2023

ruby-kramdown vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

kramdown could be made to execute arbitrary code if it received specially
crafted input.

Software Description:
- ruby-kramdown: Fast, pure-Ruby Markdown-superset converter - ruby library

Details:

It was discovered that kramdown did not restrict Rouge formatters to the
correct namespace. An attacker could use this issue to cause kramdown to
execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
   ruby-kramdown                   1.17.0-4ubuntu0.2

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-6424-1
   CVE-2021-28834

Package Information:
   https://launchpad.net/ubuntu/+source/ruby-kramdown/1.17.0-4ubuntu0.2

Ubuntu 6424-1: kramdown vulnerability

October 10, 2023
kramdown could be made to execute arbitrary code if it received specially crafted input.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: kramdown could be made to execute arbitrary code if it received specially crafted input. Software Description: - ruby-kramdown: Fast, pure-Ruby Markdown-superset converter - ruby library Details: It was discovered that kramdown did not restrict Rouge formatters to the correct namespace. An attacker could use this issue to cause kramdown to execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: ruby-kramdown 1.17.0-4ubuntu0.2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6424-1

CVE-2021-28834

Severity
Ubuntu Security Notice USN-6424-1

Package Information

https://launchpad.net/ubuntu/+source/ruby-kramdown/1.17.0-4ubuntu0.2

Related News