New version 2.3.1 is released. Note that a possible security related issue is found on the previous version of rubygem-kramdown where kramdown does not restrict custom Rouge formatters within Rouge::Formatters namespace. This issue is now assigned as CVE-2021-28834. This new rpm should fix this issue.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-139a6a2f9d 2021-03-26 00:15:07.081055 --------------------------------------------------------------------------------Name : rubygem-kramdown Product : Fedora 34 Version : 2.3.1 Release : 1.fc34 URL : Summary : Fast, pure-Ruby Markdown-superset converter Description : kramdown is yet-another-markdown-parser but fast, pure Ruby, using a strict syntax definition and supporting several common extensions. --------------------------------------------------------------------------------Update Information: New version 2.3.1 is released. Note that a possible security related issue is found on the previous version of rubygem-kramdown where kramdown does not restrict custom Rouge formatters within Rouge::Formatters namespace. This issue is now assigned as CVE-2021-28834. This new rpm should fix this issue. --------------------------------------------------------------------------------ChangeLog: * Sun Mar 21 2021 Mamoru TASAKA - 2.3.0-1 - 2.3.1 * Sun Mar 21 2021 Mamoru TASAKA - 2.3.0-3 - Apply upstream fix for CVE-2021-28834 (rouge formatter namespace restriction) --------------------------------------------------------------------------------References: [ 1 ] Bug #1941045 - CVE-2021-28834 rubygem-kramdown: allows arbitrary classes to be instantiated [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1941045 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-139a6a2f9d' at thecommand line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.