[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3480-1] ruby-redcloth security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3480-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                   Bastien Roucariès
July 06, 2023                                 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : ruby-redcloth
Version        : 4.3.2-3+deb10u1
CVE ID         : CVE-2023-31606
Debian Bug     : 1040488

A Regular Expression Denial of Service (ReDoS) issue
was discovered in the sanitize_html function of redcloth gem.
This vulnerability allows attackers to cause a Denial of Service (DoS)
via supplying a crafted payload.

For Debian 10 buster, this problem has been fixed in version
4.3.2-3+deb10u1.

We recommend that you upgrade your ruby-redcloth packages.

For the detailed security status of ruby-redcloth please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ruby-redcloth

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmSnO38ACgkQADoaLapB
CF9rPhAAnOM9Kq/rXTRL+qWQTqvxQL24NI5vnEcUQt5PIH+SHxAdSxIMdQfWqGAB
9RwJgZXNbegqke+eBkzO3SPzgi7Z+4vXc5rz4fCTj+O9fvvMuKs/D2r4wd+joKKD
Vb8Sa/AVLk07eE4LGpJ29tpx0HEmPN7+I+tqBkRDhvwgHHB8l39B/Totd+Gj9IWP
loBFlnCPo9ssKEs600ZCS33CmeRjlZZ5sSNTPKzyBZUYvghKTXrws2GCpujbO/ot
GXHM+X24HL4WK9GBd1/2hmDjN7x/BnxldALHXrGS1QVnU5GRChm7kKAIX3JxkXdn
xeapNPyMRTy9zKTYD8cBVihu13Bl0szSkQnzjTGCMXEu/BbWM9Sf7yT1HRBFqtIa
Za3wlTm4hgUbhzat7yAAPwoElvpc3r+lY4XGF2jm216Czl+hCMNKnM+rNoVGTKi8
AQW2e8CtI6ti50lx2IeDjPhsZoL4u/J+frf3Aipg5Q2/9jOQJoaTZIxuooVV2PVz
rhkqePV4U2Sqn2TxK5vA2mrtC06bopN9yiH6YGWeetfOsOOuwxYrWQOjTBp8bYZp
9oT4rYt3c0Sa76C+lj22ddOmi/n9IA8PZ44zWCNkM+vvhaD+/SQoQLdrDSbiIA/f
P7woQCRQUGCpQvFEgqmXrKVBPYPRMgFm0wB4MqiQzzRTkfEj5SY=
=M1vl
-----END PGP SIGNATURE-----


Reply to: