- Update comrak to version 0.18.0. - Disable the unused markdown support in askama and askama_shared crates, which depends on an ancient version of comrak. This update also includes fixes for two medium-severity security issues in comrak (CVE-2023-28631 and CVE-2023-28626).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-b37722768e 2023-04-29 05:12:00.195037 --------------------------------------------------------------------------------Name : rust-comrak Product : Fedora 36 Version : 0.18.0 Release : 1.fc36 URL : Summary : 100% CommonMark-compatible GitHub Flavored Markdown parser and formatter Description : A 100% CommonMark-compatible GitHub Flavored Markdown parser and formatter. --------------------------------------------------------------------------------Update Information: - Update comrak to version 0.18.0. - Disable the unused markdown support in askama and askama_shared crates, which depends on an ancient version of comrak. This update also includes fixes for two medium-severity security issues in comrak (CVE-2023-28631 and CVE-2023-28626). --------------------------------------------------------------------------------ChangeLog: * Thu Apr 20 2023 Fabio Valentini - 0.18.0-1 - Update to version 0.18.0; Fixes RHBZ#2094154 * Sat Feb 4 2023 Fabio Valentini - 0.12.1-7 - Rebuild for fixed frame pointer compiler flags in Rust RPM macros * Fri Jan 20 2023 Fedora Release Engineering - 0.12.1-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2094154 - rust-comrak-0.18.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2094154 [ 2 ] Bug #2184923 - CVE-2023-28631 rust-comrak: attacker controlled data in AST nodes is not validated [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2184923 [ 3 ] Bug #2184926 -CVE-2023-28626 rust-comrak: quadratic runtime when parsing Markdown [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2184926 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-b37722768e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- Update comrak to version 0.18.0. - Disable the unused markdown support in askama and askama_shared crates, which depends on an ancient version of comrak. This update also includes fixes for two medium-severity security issues in comrak (CVE-2023-28631 and CVE-2023-28626).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-035d5910b9 2023-04-29 02:52:14.059213 --------------------------------------------------------------------------------Name : rust-comrak Product : Fedora 38 Version : 0.18.0 Release : 1.fc38 URL : Summary : 100% CommonMark-compatible GitHub Flavored Markdown parser and formatter Description : A 100% CommonMark-compatible GitHub Flavored Markdown parser and formatter. --------------------------------------------------------------------------------Update Information: - Update comrak to version 0.18.0. - Disable the unused markdown support in askama and askama_shared crates, which depends on an ancient version of comrak. This update also includes fixes for two medium-severity security issues in comrak (CVE-2023-28631 and CVE-2023-28626). --------------------------------------------------------------------------------ChangeLog: * Thu Apr 20 2023 Fabio Valentini - 0.18.0-1 - Update to version 0.18.0; Fixes RHBZ#2094154 --------------------------------------------------------------------------------References: [ 1 ] Bug #2094154 - rust-comrak-0.18.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2094154 [ 2 ] Bug #2184923 - CVE-2023-28631 rust-comrak: attacker controlled data in AST nodes is not validated [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2184923 [ 3 ] Bug #2184926 - CVE-2023-28626 rust-comrak: quadratic runtime when parsing Markdown [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2184926 --------------------------------------------------------------------------------This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-035d5910b9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- updates `mistune` to 2.0.4 - `m2r` updated to pin dependency to `mistune < 2` - new package: `python-mistune08` compatibility package, to be used by dependents that cannot use the new mistune (namely `nbconvert`) - new package: `python-sphinx-typlog-theme`, needed to build `mistune` 2.x documentation ---- Compatibility package for mistune 0.8, so we can update mistune to 2x without. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e4f5866111 2022-11-10 22:04:44.630073 --------------------------------------------------------------------------------Name : python-mistune08 Product : Fedora 37 Version : 0.8.4 Release : 7.fc37 URL : https://github.com/lepture/mistune Summary : Markdown parser for Python Description : The fastest markdown parser in pure Python, inspired by marked. --------------------------------------------------------------------------------Update Information: - updates `mistune` to 2.0.4 - `m2r` updated to pin dependency to `mistune < 2` - new package: `python-mistune08` compatibility package, to be used by dependents that cannot use the new mistune (namely `nbconvert`) - new package: `python-sphinx-typlog-theme`, needed to build `mistune` 2.x documentation ----Compatibility package for mistune 0.8, so we can update mistune to 2x without breaking unported dependents like nbconvert --------------------------------------------------------------------------------ChangeLog: * Wed Oct 12 2022 Michel Alexandre Salim - 0.8.4-7 - Add `Obsoletes` to provide an upgrade path - Mark as deprecated() * Tue Oct 11 2022 Michel Alexandre Salim - 0.8.4-6 - New python-mistune08 compatibility package, forked off python-mistune * Fri Jul 22 2022 Fedora Release Engineering - 0.8.4-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Mon Jun 13 2022 Python Maint - 0.8.4-4 - Rebuilt for Python 3.11 * Fri Jan 21 2022 Fedora Release Engineering - 0.8.4-3 -Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Fri Jul 23 2021 Fedora Release Engineering - 0.8.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild * Fri Jul 9 2021 Tomas Hrnciar - 0.8.4-1 - Update to 0.8.4 * Fri Jun 4 2021 Python Maint - 0.8.3-16 - Rebuilt for Python 3.10 * Mon Feb 8 2021 Charalampos Stratakis - 0.8.3-15 - Run the tests with pytest instead of nose * Wed Jan 27 2021 Fedora Release Engineering - 0.8.3-14 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1782288 - python-mistune-2.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1782288 [ 2 ] Bug #2112232 - CVE-2022-34749 python-mistune: mistune: catastrophic backtracking [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2112232 [ 3 ] Bug #2133872 - Review Request: python-mistune08 - Markdown parser for Python https://bugzilla.redhat.com/show_bug.cgi?id=2133872 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-e4f5866111' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Stan Hu discovered that kramdown, a pure Ruby Markdown parser and converter, performed insufficient namespace validation of Rouge syntax highlighting formatters. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4890-1
Update to latest upstream release, fix CVE-2019-9844 (rhbz#1695304,. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-bce274cbf6 2019-04-09 00:01:39.900922 --------------------------------------------------------------------------------Name : nodejs-simple-markdown Product : Fedora 30 Version : 0.4.4 Release : 1.fc30 URL : https://www.npmjs.com/package/simple-markdown Summary : Javascript markdown parsing, made simple Description : simple-markdown is a markdown-like parser designed for simplicity and extensibility. --------------------------------------------------------------------------------Update Information: Update to latest upstream release, fix CVE-2019-9844 (rhbz#1695304, --------------------------------------------------------------------------------References: [ 1 ] Bug #1695303 - CVE-2019-9844 nodejs-simple-markdown: Cross-site script through the data of a vbscript link https://bugzilla.redhat.com/show_bug.cgi?id=1695303 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-bce274cbf6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.