-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- ------------------------------------------------------------------------- Debian Security Advisory DSA-4890-1
security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff
April 12, 2021
https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : ruby-kramdown
CVE ID : CVE-2021-28834
Debian Bug : 985569
Stan Hu discovered that kramdown, a pure Ruby Markdown parser and
converter, performed insufficient namespace validation of Rouge syntax highlighting formatters.
For the stable distribution (buster), this problem has been fixed in
version 1.17.0-1+deb10u2.
We recommend that you upgrade your ruby-kramdown packages.
For the detailed security status of ruby-kramdown please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ruby-kramdown
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at:
https://www.debian.org/security/
Mailing list:
debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmBz9QcACgkQEMKTtsN8 TjYwUQ/9FgrqEyW3zffj1G1mRdNZZZqRZTq1Oi6kokJkvAUHYvz9ZDzwcnJWXvUz tQmz59/EKg8BrHJvaV+q64U/qLRpYdVfDLioKlKkRh+k3chEd66/2HrNpvtIrWoO QcB9SPVHLxz/hBzJ99hCJC2FF0/HEUXpvWUK6LmZ4WS8ZLuObnDK4Yx12naFRCh7 w2x8gUapZVxn5VzH+JAA6CRra4ktHYvA2r2VRII8JH6KkST/lE8I/sodEGjM9QB+ /zz4avti/qZI81ik35Ow4hxLYOkXmS+Oyt+6oNUX66t/4yvtrfnSNloXHbcyE6hN GeFR6KgZN21KImJODnG+3lfWgvwW6Lo2WfJiHiiCDAYH1D7C+J7fj3smj5qSBKeg rRa2GHgPMQPKKREARsg9aeIWq1n3aNQ3ul0tMLFCsm6jjpKTObyj/GHOS9zi5NpL pb5+4AWhkSgxJXjehm+N0sSJSjs1wPuo0SgOek/tHDMuKRwN9jRC3Qqz5Z1fz4VI 9Ft6sbq/WtgIyhvsd0+LOcRe9PId9ymBlict/XaGd/kadHuanT+W+soTeQMU1jtd vFX9WQGVDM3l0v1r1DfQzU7iYcqB1jgsObUvpubbuKnhMWnIibnZ+AZDjJItQ+HR i/ZZWYcXka8RVTCiENYT7fOpp2V26iKUFcAtXRetzwtXc20lbNc=
=gT1P
-----END PGP SIGNATURE-----
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)