USN-6424-1: kramdown vulnerability
Published Oct 10, 2023
·Updated
It was discovered that kramdown did not restrict Rouge formatters to the correct namespace. An attacker could use this issue to cause kramdown to execute arbitrary code.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/ruby-kramdown<1.17.0-4ubuntu0.2
1.17.0-4ubuntu0.2
Ubuntu Ubuntu=20.04
Event History
Oct 10, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for the kramdown vulnerability?
The vulnerability ID for the kramdown vulnerability is USN-6424-1.
2
What is the severity of the kramdown vulnerability?
The severity of the kramdown vulnerability is not specified in the information provided.
3
How does the kramdown vulnerability allow for arbitrary code execution?
The kramdown vulnerability allows for arbitrary code execution by not restricting Rouge formatters to the correct namespace.
4
What software is affected by the kramdown vulnerability?
The software affected by the kramdown vulnerability is ruby-kramdown version 1.17.0-4ubuntu0.2 on Ubuntu 20.04.
5
How can I fix the kramdown vulnerability?
To fix the kramdown vulnerability, upgrade to version 1.17.0-4ubuntu0.2 of the ruby-kramdown package.