ALSA-2022:5597
Dashboard / Vulnerabilities / ALSA-2022:5597
Summary: Important: pandoc security update
Details: Pandoc is a markdown/markup conversion tool. The version of pandoc in AlmaLinux 8 CRB uses cmark-gfm (GitHub's extended version of the C reference implementation of CommonMark) for parts of its conversion. The update, fixes CVE-2022-24724: an integer overflow in cmark-gfm's table row parsing which may lead to heap memory corruption when parsing tables with more than UINT16_MAX columns. Security Fix(es): * cmark-gfm: possible RCE due to integer overflow (CVE-2022-24724) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2022:5597, https://access.redhat.com/security/cve/CVE-2022-24724, https://bugzilla.redhat.com/2060662, https://errata.almalinux.org/8/ALSA-2022-5597.html
Affected packages
Package
Name: pandoc
Purl: pkg:rpm/almalinux/pandoc
Affected ranges
Type: ECOSYSTEM
Events:
