Advisories ยป MGASA-2023-0181

Updated cmark packages fix security vulnerability

Publication date: 21 May 2023
Modification date: 21 May 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2023-22484 , CVE-2023-22486

Description

cmark incorrectly handled certain inputs. Fixes quadratic complexity in
handle_close_bracket "![[]()" which may lead to a denial of service
(CVE-2023-22486).
Noting that this also fixes a quadratic parsing issue with repeated comment
tags that was not in a released product but which was assigned a CVE
(CVE-2023-22484).
                

References

SRPMS

8/core