• [SECURITY] [DSA 4890-1] ruby-kramdown security update

    From Moritz Muehlenhoff@21:1/5 to All on Mon Apr 12 09:30:02 2021
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4890-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff
    April 12, 2021 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : ruby-kramdown
    CVE ID : CVE-2021-28834
    Debian Bug : 985569

    Stan Hu discovered that kramdown, a pure Ruby Markdown parser and
    converter, performed insufficient namespace validation of Rouge syntax highlighting formatters.

    For the stable distribution (buster), this problem has been fixed in
    version 1.17.0-1+deb10u2.

    We recommend that you upgrade your ruby-kramdown packages.

    For the detailed security status of ruby-kramdown please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/ruby-kramdown

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmBz9QcACgkQEMKTtsN8 TjYwUQ/9FgrqEyW3zffj1G1mRdNZZZqRZTq1Oi6kokJkvAUHYvz9ZDzwcnJWXvUz tQmz59/EKg8BrHJvaV+q64U/qLRpYdVfDLioKlKkRh+k3chEd66/2HrNpvtIrWoO QcB9SPVHLxz/hBzJ99hCJC2FF0/HEUXpvWUK6LmZ4WS8ZLuObnDK4Yx12naFRCh7 w2x8gUapZVxn5VzH+JAA6CRra4ktHYvA2r2VRII8JH6KkST/lE8I/sodEGjM9QB+ /zz4avti/qZI81ik35Ow4hxLYOkXmS+Oyt+6oNUX66t/4yvtrfnSNloXHbcyE6hN GeFR6KgZN21KImJODnG+3lfWgvwW6Lo2WfJiHiiCDAYH1D7C+J7fj3smj5qSBKeg rRa2GHgPMQPKKREARsg9aeIWq1n3aNQ3ul0tMLFCsm6jjpKTObyj/GHOS9zi5NpL pb5+4AWhkSgxJXjehm+N0sSJSjs1wPuo0SgOek/tHDMuKRwN9jRC3Qqz5Z1fz4VI 9Ft6sbq/WtgIyhvsd0+LOcRe9PId9ymBlict/XaGd/kadHuanT+W+soTeQMU1jtd vFX9WQGVDM3l0v1r1DfQzU7iYcqB1jgsObUvpubbuKnhMWnIibnZ+AZDjJItQ+HR i/ZZWYcXka8RVTCiENYT7fOpp2V26iKUFcAtXRetzwtXc20lbNc=
    =gT1P
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)