GHSA-c2v4-chx5-vff6

Suggest an improvement
Source
https://github.com/advisories/GHSA-c2v4-chx5-vff6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-c2v4-chx5-vff6/GHSA-c2v4-chx5-vff6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c2v4-chx5-vff6
Withdrawn
2024-01-05T15:31:42Z
Published
2024-01-04T21:30:24Z
Modified
2026-09-10T03:49:24Z
Summary
Duplicate Advisory: Integer overflow in cmark-gfm table parsing extension leads to heap memory corruption
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-fmx4-26r3-wxpf. This link is maintained to preserve external references.

Original Description

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

Database specific
{
    "cwe_ids": [
        "CWE-190"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-05T15:31:42Z",
    "nvd_published_at": "2024-01-04T21:15:10Z",
    "severity": "HIGH"
}
References

Affected packages

RubyGems / commonmarker

Package

Name
commonmarker
Purl
pkg:gem/commonmarker

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
0.9.2
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.14.11
0.14.12
0.14.13
0.14.14
0.14.15
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.17.6
0.17.7
0.17.7.1
0.17.8
0.17.9
0.17.10
0.17.11
0.17.12
0.17.13
0.18.0
0.18.1
0.18.2
0.19.0
0.20.0
0.20.1
0.20.2
0.21.0
0.21.1
0.21.2
0.22.0
0.23.0
0.23.1
0.23.2
0.23.4
0.23.5
0.23.6
0.23.7.pre1
0.23.7
0.23.8
0.23.9
0.23.10
0.23.11
0.23.12
1.*
1.0.0.pre
1.0.0.pre.2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.0.0.pre6
1.0.0.pre7
1.0.0.pre8
1.0.0.pre9
1.0.0.pre10
1.0.0.pre11
1.0.0.pre12
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
2.*
2.0.0
2.0.1
2.0.2
2.0.2.1
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.10.0

Database specific

last_known_affected_version_range
"< 0.23.4"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-c2v4-chx5-vff6/GHSA-c2v4-chx5-vff6.json"