CVE-2023-24824

CVSS V2 None CVSS V3 None
Description
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing text which leads with either large numbers of `>` or `-` characters. This issue has been addressed in version 0.29.0.gfm.10. Users are advised to upgrade. Users unable to upgrade should validate that their input comes from trusted sources.
Overview
  • CVE ID
  • CVE-2023-24824
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-31T23:15:07
  • Last Modified Date
  • 2023-04-11T06:25:18
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:github:cmark-gfm:*:*:*:*:*:*:*:* 1 OR 0.29.0.gfm.10.
History
Created Old Value New Value Data Type Notes
2023-04-17 03:58:49 Added to TrackCVE
2023-04-17 03:58:52 Weakness Enumeration new