[Git][security-tracker-team/security-tracker][master] Update status for CVE-2023-37463/ruby-commonmarker

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 23 17:36:44 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
782aa0ff by Salvatore Bonaccorso at 2025-09-23T18:36:04+02:00
Update status for CVE-2023-37463/ruby-commonmarker

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -216108,12 +216108,13 @@ CVE-2023-37463 (cmark-gfm is an extended version of the C reference implementati
 	[bookworm] - r-cran-commonmark <ignored> (Minor issue)
 	[bullseye] - r-cran-commonmark <no-dsa> (Minor issue)
 	[buster] - r-cran-commonmark <no-dsa> (Minor issue)
-	- ruby-commonmarker <unfixed> (bug #1041100)
-	[trixie] - ruby-commonmarker <ignored> (Minor issue)
+	- ruby-commonmarker 0.23.10-1 (bug #1041100)
 	[bookworm] - ruby-commonmarker <ignored> (Minor issue)
 	[bullseye] - ruby-commonmarker <no-dsa> (Minor issue)
 	[buster] - ruby-commonmarker <no-dsa> (Minor issue)
 	NOTE: https://github.com/github/cmark-gfm/security/advisories/GHSA-w4qg-3vf7-m9x5
+	NOTE: https://github.com/github/cmark-gfm/commit/38d1cfeba3ce457da53e77f9712dfbce95d8558c (0.29.0.gfm.12)
+	NOTE: https://github.com/gjtorikian/commonmarker/commit/db8cd377b54541f7fd484d168b7682a282a680f7 (v0.23.10)
 	NOTE: https://github.com/theacodes/cmarkgfm/commit/acf473a51a9dc3a4fd6d6a4b30e4d80c94d91d4a (2024.1.14)
 	NOTE: r-cran-commonmark: https://github.com/r-lib/commonmark/commit/969e27ea29dce1c2d7ab9b9909640bb4643d460f (v1.9.1)
 CVE-2023-37267 (Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco c ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/782aa0fff20f922f0dc70bf4f69b3e16b16f67bc

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/782aa0fff20f922f0dc70bf4f69b3e16b16f67bc
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250923/fbd81175/attachment.htm>


More information about the debian-security-tracker-commits mailing list