CVE-2023-37463: Quadratic complexity bugs may lead to a denial of service
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. These vulnerabilities have been patched in 0.29.0.gfm.12.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
cmark-gfmto a version that resolves this vulnerability.Fixed in 0.29.0.gfm.12
Event History
Frequently Asked Questions
What is CVE-2023-37463?
CVE-2023-37463 is a vulnerability in cmark-gfm, an extended version of the C reference implementation of CommonMark.
How severe is CVE-2023-37463?
CVE-2023-37463 has a severity rating of 7.5, which is considered high.
What is affected by CVE-2023-37463?
CVE-2023-37463 affects cmark-gfm version 0.29.0.gfm.12 and earlier.
How can I fix CVE-2023-37463?
To fix CVE-2023-37463, update cmark-gfm to version 0.29.0.gfm.13 or later.
Where can I find more information about CVE-2023-37463?
You can find more information about CVE-2023-37463 on the GitHub security advisory page and the GitHub release page for cmark-gfm version 0.29.0.gfm.12.