Unrated severityNVD Advisory· Published Jul 13, 2023· Updated Oct 30, 2024
Quadratic complexity bugs may lead to a denial of service
CVE-2023-37463
Description
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. These vulnerabilities have been patched in 0.29.0.gfm.12.
Affected products
5- osv-coords4 versionspkg:deb/ubuntu/cmark-gfm@0.29.0.gfm.0-4?arch=source&distro=focalpkg:deb/ubuntu/cmark-gfm@0.29.0.gfm.3-3?arch=source&distro=jammypkg:deb/ubuntu/cmark-gfm@0.29.0.gfm.6-6build1?arch=source&distro=noblepkg:deb/ubuntu/cmark-gfm@0.29.0.gfm.6-6build1?arch=source&distro=oracular
>= 0+ 3 more
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.12mitrex_refsource_MISC
- github.com/github/cmark-gfm/security/advisories/GHSA-w4qg-3vf7-m9x5mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.