Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-44337

Опубликовано: 15 окт. 2024
Источник: redhat
CVSS3: 5.3

Описание

The package github.com/gomarkdown/markdown is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion v0.0.0-20240729232818-a2a9c4f, which corresponds with commit a2a9c4f76ef5a5c32108e36f7c47f8d310322252, there was a logical problem in the paragraph function of the parser/block.go file, which allowed a remote attacker to cause a denial of service (DoS) condition by providing a tailor-made input that caused an infinite loop, causing the program to hang and consume resources indefinitely. Submit a2a9c4f76ef5a5c32108e36f7c47f8d310322252 contains fixes to this problem.

A flaw was found in the github.com/gomarkdown/markdown Golang library. There is a logical problem with the paragraph function of the parser/block.go file. This flaw allows a remote attacker to trigger a denial of service (DoS) by providing a specially crafted input, causing an infinite loop condition. This issue can cause the program to hang and consume resources indefinitely.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Kube Descheduler Operatorkube-descheduler-operator/descheduler-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/lokistack-gateway-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/kube-metrics-server-rhel8Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-deschedulerNot affected
Red Hat OpenShift distributed tracing 3rhosdt/tempo-gateway-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2318862gomarkdown/markdown: infinite loop via the paragraph function of parser/block.go

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.1
ubuntu
больше 1 года назад

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there was a logical problem in the paragraph function of the parser/block.go file, which allowed a remote attacker to cause a denial of service (DoS) condition by providing a tailor-made input that caused an infinite loop, causing the program to hang and consume resources indefinitely. Submit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252` contains fixes to this problem.

CVSS3: 5.1
nvd
больше 1 года назад

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there was a logical problem in the paragraph function of the parser/block.go file, which allowed a remote attacker to cause a denial of service (DoS) condition by providing a tailor-made input that caused an infinite loop, causing the program to hang and consume resources indefinitely. Submit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252` contains fixes to this problem.

CVSS3: 5.1
msrc
4 месяца назад

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there was a logical problem in the paragraph function of the parser/block.go file, which allowed a remote attacker to cause a denial of service (DoS) condition by providing a tailor-made input that caused an infinite loop, causing the program to hang and consume resources indefinitely. Submit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252` contains fixes to this problem.

CVSS3: 5.1
debian
больше 1 года назад

The package `github.com/gomarkdown/markdown` is a Go library for parsi ...

CVSS3: 5.1
github
около 1 года назад

Infinite loop in github.com/gomarkdown/markdown

5.3 Medium

CVSS3