RSEC-2023-7

See a problem?
Import Source
https://github.com/RConsortium/r-advisory-database/blob/main/vulns/commonmark/RSEC-2023-7.yaml
JSON Data
https://api.osv.dev/v1/vulns/RSEC-2023-7
Published
2023-10-06T05:00:00.600Z
Modified
2023-10-20T07:27:00.600Z
Summary
Denial of Service (DoS) and Arbitrary Code Execution (ACE) vulnerabilities
Details

cmark-gfm, GitHub's extended CommonMark library, has multiple vulnerabilities. Versions prior to 0.29.0.gfm.6 suffer from a polynomial time complexity issue in the autolink extension, causing denial of service. Also, versions before 0.29.0.gfm.3 and 0.28.3.gfm.21 contain an integer overflow in table row parsing, leading to heap corruption and potential Arbitrary Code Execution. Patches are available in versions 0.29.0.gfm.6, 0.29.0.gfm.3, and 0.28.3.gfm.21. Mitigations include upgrading or disabling affected extensions.

References

Affected packages

CRAN / commonmark

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.2
Fixed
1.8

Affected versions

0.*

0.2
0.4
0.5
0.6
0.7
0.8
0.9

1.*

1.0
1.1
1.2
1.4
1.5
1.6
1.7