-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4890-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 12, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ruby-kramdown CVE ID : CVE-2021-28834 Debian Bug : 985569 Stan Hu discovered that kramdown, a pure Ruby Markdown parser and converter, performed insufficient namespace validation of Rouge syntax highlighting formatters. For the stable distribution (buster), this problem has been fixed in version 1.17.0-1+deb10u2. We recommend that you upgrade your ruby-kramdown packages. For the detailed security status of ruby-kramdown please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ruby-kramdown Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmBz9QcACgkQEMKTtsN8 TjYwUQ/9FgrqEyW3zffj1G1mRdNZZZqRZTq1Oi6kokJkvAUHYvz9ZDzwcnJWXvUz tQmz59/EKg8BrHJvaV+q64U/qLRpYdVfDLioKlKkRh+k3chEd66/2HrNpvtIrWoO QcB9SPVHLxz/hBzJ99hCJC2FF0/HEUXpvWUK6LmZ4WS8ZLuObnDK4Yx12naFRCh7 w2x8gUapZVxn5VzH+JAA6CRra4ktHYvA2r2VRII8JH6KkST/lE8I/sodEGjM9QB+ /zz4avti/qZI81ik35Ow4hxLYOkXmS+Oyt+6oNUX66t/4yvtrfnSNloXHbcyE6hN GeFR6KgZN21KImJODnG+3lfWgvwW6Lo2WfJiHiiCDAYH1D7C+J7fj3smj5qSBKeg rRa2GHgPMQPKKREARsg9aeIWq1n3aNQ3ul0tMLFCsm6jjpKTObyj/GHOS9zi5NpL pb5+4AWhkSgxJXjehm+N0sSJSjs1wPuo0SgOek/tHDMuKRwN9jRC3Qqz5Z1fz4VI 9Ft6sbq/WtgIyhvsd0+LOcRe9PId9ymBlict/XaGd/kadHuanT+W+soTeQMU1jtd vFX9WQGVDM3l0v1r1DfQzU7iYcqB1jgsObUvpubbuKnhMWnIibnZ+AZDjJItQ+HR i/ZZWYcXka8RVTCiENYT7fOpp2V26iKUFcAtXRetzwtXc20lbNc= =gT1P -----END PGP SIGNATURE-----