-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3480-1 [email protected] https://www.debian.org/lts/security/ Bastien Roucariès July 06, 2023 https://wiki.debian.org/LTS - -------------------------------------------------------------------------
Package : ruby-redcloth Version : 4.3.2-3+deb10u1 CVE ID : CVE-2023-31606 Debian Bug : 1040488 A Regular Expression Denial of Service (ReDoS) issue was discovered in the sanitize_html function of redcloth gem. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. For Debian 10 buster, this problem has been fixed in version 4.3.2-3+deb10u1. We recommend that you upgrade your ruby-redcloth packages. For the detailed security status of ruby-redcloth please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ruby-redcloth Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmSnO38ACgkQADoaLapB CF9rPhAAnOM9Kq/rXTRL+qWQTqvxQL24NI5vnEcUQt5PIH+SHxAdSxIMdQfWqGAB 9RwJgZXNbegqke+eBkzO3SPzgi7Z+4vXc5rz4fCTj+O9fvvMuKs/D2r4wd+joKKD Vb8Sa/AVLk07eE4LGpJ29tpx0HEmPN7+I+tqBkRDhvwgHHB8l39B/Totd+Gj9IWP loBFlnCPo9ssKEs600ZCS33CmeRjlZZ5sSNTPKzyBZUYvghKTXrws2GCpujbO/ot GXHM+X24HL4WK9GBd1/2hmDjN7x/BnxldALHXrGS1QVnU5GRChm7kKAIX3JxkXdn xeapNPyMRTy9zKTYD8cBVihu13Bl0szSkQnzjTGCMXEu/BbWM9Sf7yT1HRBFqtIa Za3wlTm4hgUbhzat7yAAPwoElvpc3r+lY4XGF2jm216Czl+hCMNKnM+rNoVGTKi8 AQW2e8CtI6ti50lx2IeDjPhsZoL4u/J+frf3Aipg5Q2/9jOQJoaTZIxuooVV2PVz rhkqePV4U2Sqn2TxK5vA2mrtC06bopN9yiH6YGWeetfOsOOuwxYrWQOjTBp8bYZp 9oT4rYt3c0Sa76C+lj22ddOmi/n9IA8PZ44zWCNkM+vvhaD+/SQoQLdrDSbiIA/f P7woQCRQUGCpQvFEgqmXrKVBPYPRMgFm0wB4MqiQzzRTkfEj5SY= =M1vl -----END PGP SIGNATURE-----
