[Git][security-tracker-team/security-tracker][master] Update information for CVE-2023-31606/ruby-redcloth

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jan 13 20:00:54 GMT 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
90c3884c by Salvatore Bonaccorso at 2024-01-13T21:00:16+01:00
Update information for CVE-2023-31606/ruby-redcloth

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -34485,10 +34485,12 @@ CVE-2023-32203 (The affected application lacks proper validation of user-supplie
 	NOT-FOR-US: Horner Automation
 CVE-2023-31606 (A Regular Expression Denial of Service (ReDoS) issue was discovered in ...)
 	{DLA-3480-1}
-	- ruby-redcloth <unfixed> (bug #1040488)
+	- ruby-redcloth 4.3.3-1 (bug #1040488)
 	[bookworm] - ruby-redcloth <no-dsa> (Minor issue)
 	[bullseye] - ruby-redcloth <no-dsa> (Minor issue)
 	NOTE: https://github.com/jgarber/redcloth/issues/73
+	NOTE: https://github.com/jgarber/redcloth/pull/75
+	NOTE: https://github.com/jgarber/redcloth/commit/8b1327688fef8e6617792054ef299d7bc74c0a1e (v4.3.3)
 	NOTE: https://github.com/e23e/CVE-2023-31606#readme
 CVE-2023-31569 (TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a co ...)
 	NOT-FOR-US: TOTOLINK



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/90c3884cd63f7ea2447be8fe000cdd982daf6be3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/90c3884cd63f7ea2447be8fe000cdd982daf6be3
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240113/ce8dafd0/attachment.htm>


More information about the debian-security-tracker-commits mailing list