USN-4562-2: kramdown vulnerability
Published Oct 26, 2020
·Updated
It was discovered that kramdown insecurely handled certain crafted input. An attacker could use this vulnerability to read restricted files or execute arbitrary code.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/kramdown<1.17.0-4ubuntu0.20.10.1
1.17.0-4ubuntu0.20.10.1
Ubuntu Ubuntu=20.10
All of the following
ubuntu/ruby-kramdown<1.17.0-4ubuntu0.20.10.1
1.17.0-4ubuntu0.20.10.1
Ubuntu Ubuntu=20.10
Event History
Oct 26, 2020
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this kramdown vulnerability?
The vulnerability ID for this kramdown vulnerability is USN-4562-2.
2
What is the severity of the kramdown vulnerability?
The severity of the kramdown vulnerability is not mentioned in the information provided.
3
What software is affected by this kramdown vulnerability?
The kramdown vulnerability affects the kramdown package and the ruby-kramdown package on Ubuntu 20.10.
4
How can an attacker exploit this kramdown vulnerability?
An attacker could exploit this kramdown vulnerability to read restricted files or execute arbitrary code.
5
How can I fix the kramdown vulnerability?
To fix the kramdown vulnerability, update the kramdown package and the ruby-kramdown package to version 1.17.0-4ubuntu0.20.10.1 or later.