Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTczMjItOW14Ni01ajJt

redcarpet Buffer Overflow vulnerability

Stack-based buffer overflow in the header_anchor function in the HTML renderer in Redcarpet before 3.3.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

Permalink: https://github.com/advisories/GHSA-7322-9mx6-5j2m
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTczMjItOW14Ni01ajJt
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 5 years ago
Updated: 6 months ago


Identifiers: GHSA-7322-9mx6-5j2m, CVE-2015-5147
References:

Affected Packages

rubygems:redcarpet
Versions: >= 3.3.0, < 3.3.2
Fixed in: 3.3.2