From 6a4408b9bbd9fe61dc0966f587db94081fa5f52b Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Wed, 10 Jan 2024 19:03:44 +0000 Subject: gentoo auto-resync : 10:01:2024 - 19:03:44 --- metadata/glsa/glsa-202401-14.xml | 42 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 metadata/glsa/glsa-202401-14.xml (limited to 'metadata/glsa/glsa-202401-14.xml') diff --git a/metadata/glsa/glsa-202401-14.xml b/metadata/glsa/glsa-202401-14.xml new file mode 100644 index 000000000000..8489fd1909cd --- /dev/null +++ b/metadata/glsa/glsa-202401-14.xml @@ -0,0 +1,42 @@ + + + + RedCloth: ReDoS Vulnerability + A denial of service vulnerability has been found in RedCloth. + redcloth + 2024-01-10 + 2024-01-10 + 908035 + remote + + + 4.3.2-r5 + 4.3.2-r5 + + + +

RedCloth is a module for using Textile in Ruby

+
+ +

A vulnerability has been discovered in RedCloth. Please review the CVE identifier referenced below for details.

+
+ +

RedCloth is vulnerable to a regular expression denial of service ("ReDoS") attack via the sanitize_html function.

+
+ +

There is no known workaround at this time.

+
+ +

All RedCloth users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-ruby/redcloth-4.3.2-r5" + +
+ + CVE-2023-31606 + + ajak + graaff +
\ No newline at end of file -- cgit v1.2.3