Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTczMjItOW14Ni01ajJt
redcarpet Buffer Overflow vulnerability
Stack-based buffer overflow in the header_anchor
function in the HTML renderer in Redcarpet before 3.3.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTczMjItOW14Ni01ajJt
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 5 years ago
Updated: 6 months ago
Identifiers: GHSA-7322-9mx6-5j2m, CVE-2015-5147
References:
- https://nvd.nist.gov/vuln/detail/CVE-2015-5147
- https://github.com/vmg/redcarpet/blob/master/CHANGELOG.md
- http://www.openwall.com/lists/oss-security/2015/06/29/3
- http://www.openwall.com/lists/oss-security/2015/06/30/10
- https://web.archive.org/web/20150711061256/http://www.securityfocus.com/bid/75508
- https://github.com/vmg/redcarpet/commit/2cee777c1e5babe8a1e2683d31ea75cc4afe55fb
- https://github.com/advisories/GHSA-7322-9mx6-5j2m
Affected Packages
rubygems:redcarpet
Versions: >= 3.3.0, < 3.3.2Fixed in: 3.3.2