Debian Security Advisory
DSA-4890-1 ruby-kramdown -- security update
- Date Reported:
- 12 Apr 2021
- Affected Packages:
- ruby-kramdown
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 985569.
In Mitre's CVE dictionary: CVE-2021-28834. - More information:
-
Stan Hu discovered that kramdown, a pure Ruby Markdown parser and converter, performed insufficient namespace validation of Rouge syntax highlighting formatters.
For the stable distribution (buster), this problem has been fixed in version 1.17.0-1+deb10u2.
We recommend that you upgrade your ruby-kramdown packages.
For the detailed security status of ruby-kramdown please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ruby-kramdown