Bug#1041976: pandoc: CVE-2023-35936

2023-07-25 Thread Jonas Smedegaard
Quoting Guilhem Moulin (2023-07-25 23:46:17) > On Tue, 25 Jul 2023 at 14:39:29 +0200, Jonas Smedegaard wrote: > > I have no objections at all - on the contrary: Thanks! > > > > I will have a look at applying the patch to trixie, then - since there > > is unfortunately little hope that the whole

Bug#1041976: pandoc: CVE-2023-35936

2023-07-25 Thread Guilhem Moulin
On Tue, 25 Jul 2023 at 14:39:29 +0200, Jonas Smedegaard wrote: > I have no objections at all - on the contrary: Thanks! > > I will have a look at applying the patch to trixie, then - since there > is unfortunately little hope that the whole Haskell stack will get > upgrading any time soon, so wi

Bug#1041976: pandoc: CVE-2023-35936

2023-07-25 Thread Jonas Smedegaard
Quoting Guilhem Moulin (2023-07-25 13:34:52) > The following vulnerability was published for pandoc. > > CVE-2023-35936[0]: > | Starting in version 1.13 and prior to version 3.1.4, Pandoc is > | susceptible to an arbitrary file write vulnerability, which can be > | triggered by providing a

Bug#1041976: pandoc: CVE-2023-35936

2023-07-25 Thread Guilhem Moulin
Package: pandoc Version: 2.17.1.1-1.1 Severity: important Tags: security upstream patch Control: found -1 2.2.1-3 Control: found -1 2.9.2.1-1 X-Debbugs-Cc: guil...@debian.org Hi, The following vulnerability was published for pandoc. CVE-2023-35936[0]: | Starting in version 1.13 and prior to