-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2316-1 [email protected] https://www.debian.org/lts/security/ Abhijith PA August 08, 2020 https://wiki.debian.org/LTS - -------------------------------------------------------------------------
Package : ruby-kramdown Version : 1.12.0-1+deb9u1 CVE ID : CVE-2020-14001 Debian Bug : 965305 ruby-kramdown processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. For Debian 9 stretch, this problem has been fixed in version 1.12.0-1+deb9u1. We recommend that you upgrade your ruby-kramdown packages. For the detailed security status of ruby-kramdown please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ruby-kramdown Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAl8vZqMACgkQhj1N8u2c KO/Esw/7BTBQUguNywZEMycrYKksRnWJCeUN4xvx4U4W182sJ6ffDrT7JuR9t+/c IeNX9RA142EhTQFoXwruEMjWoSV8yeU1UiIsbsOt8OrELlGIz2zPsIoQcI7QZZIZ oun51743Z5Q111DyWWOpLIEVTi67kPsAP+Vy7m/1sB0XPXjOj0uSYzznnvDHjp91 60EaLDawwnJ8roZ61A7/RyYG57MkztBAwyIN9KwaTc3YTnsmTq/vJ/LDb/hWKEoL ZsaSnmEnjODqEeiZfXT00Sn2oCm5cHyI5d2JcCgxU9WAkrG7ISlbuLMIu8zgqwJH zUc/N50ufcjZ7lPYLjEtL/TQNTmTX+sMskk5obUacIoIT3ojOSen1/0aCGoYoTgn pLYK0JsMPe0sIkDQ15BGWt8Jyp7VKzTIL189Oolv3+c2xbktpuos4QLs2jvofu3N 9LQnXzlGOyekOXESmegXEjXjJPVwTjeC7NUudu5bpz1auo4faoW+HmU9pbY5dfs4 awJjWCklXAmtH+iyYhwVv/hediHDbQiZpqTVEzKgEyYthHJAedni1JMV410K8Hfh bJimwwb8yykd3CfEibtUcy6poqgS8TVxjAYO+2GZVF1bWkZA49LPK6bTwo40u4Nb k5YPlaAc25G2sSyCr6uRs4m2Sk9DNl/TXBGGNT0XQJC7WmZuZHU= =lehn -----END PGP SIGNATURE-----
