Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-39209

Опубликовано: 15 сент. 2022
Источник: debian
EPSS Низкий

Описание

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service. Users may verify the patch by running `python3 -c 'print("![l"* 100000 + "\n")' | ./cmark-gfm -e autolink`, which will resource exhaust on unpatched cmark-gfm but render correctly on patched cmark-gfm. This vulnerability has been patched in 0.29.0.gfm.6. Users are advised to upgrade. Users unable to upgrade should disable the use of the autolink extension.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cmark-gfmfixed0.29.0.gfm.6-2package
cmark-gfmignoredbookwormpackage
cmark-gfmno-dsabullseyepackage
cmark-gfmno-dsabusterpackage
python-cmarkgfmfixed2024.11.20-1package
python-cmarkgfmno-dsabookwormpackage
python-cmarkgfmno-dsabullseyepackage
python-cmarkgfmno-dsabusterpackage
ghostwriterfixed2.1.6+ds-1package
ruby-commonmarkerfixed0.23.10-1package
ruby-commonmarkerignoredbookwormpackage
ruby-commonmarkerno-dsabullseyepackage
ruby-commonmarkerno-dsabusterpackage
r-cran-commonmarkfixed1.8.1-1package
r-cran-commonmarkno-dsabullseyepackage
r-cran-commonmarkno-dsabusterpackage

Примечания

  • https://github.com/github/cmark-gfm/security/advisories/GHSA-cgh3-p57x-9q7q

  • https://github.com/github/cmark-gfm/commit/cfcaa0068bf319974fdec283416fcee5035c2d70 (0.29.0.gfm.6)

  • For ghostwriter just a hang/crash in GUI tool, no security impact

  • https://github.com/theacodes/cmarkgfm/commit/d6bb964c5b27ecf5deb76f0d1ce5e9274cb877ff (2022.10.27)

EPSS

Процентиль: 78%
0.01103
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service. Users may verify the patch by running `python3 -c 'print("![l"* 100000 + "\n")' | ./cmark-gfm -e autolink`, which will resource exhaust on unpatched cmark-gfm but render correctly on patched cmark-gfm. This vulnerability has been patched in 0.29.0.gfm.6. Users are advised to upgrade. Users unable to upgrade should disable the use of the autolink extension.

CVSS3: 6.5
redhat
больше 3 лет назад

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service. Users may verify the patch by running `python3 -c 'print("![l"* 100000 + "\n")' | ./cmark-gfm -e autolink`, which will resource exhaust on unpatched cmark-gfm but render correctly on patched cmark-gfm. This vulnerability has been patched in 0.29.0.gfm.6. Users are advised to upgrade. Users unable to upgrade should disable the use of the autolink extension.

CVSS3: 7.5
nvd
больше 3 лет назад

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service. Users may verify the patch by running `python3 -c 'print("![l"* 100000 + "\n")' | ./cmark-gfm -e autolink`, which will resource exhaust on unpatched cmark-gfm but render correctly on patched cmark-gfm. This vulnerability has been patched in 0.29.0.gfm.6. Users are advised to upgrade. Users unable to upgrade should disable the use of the autolink extension.

EPSS

Процентиль: 78%
0.01103
Низкий