DSA-4890-1 ruby-kramdown -- security update

Related Vulnerabilities: CVE-2021-28834  

Stan Hu discovered that kramdown, a pure Ruby Markdown parser and converter, performed insufficient namespace validation of Rouge syntax highlighting formatters. For the stable distribution (buster), this problem has been fixed in version 1.17.0-1+deb10u2. We recommend that you upgrade your ruby-kramdown packages. For the detailed security status of ruby-kramdown please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ruby-kramdown

Debian Security Advisory

DSA-4890-1 ruby-kramdown -- security update

Date Reported:
12 Apr 2021
Affected Packages:
ruby-kramdown
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 985569.
In Mitre's CVE dictionary: CVE-2021-28834.
More information:

Stan Hu discovered that kramdown, a pure Ruby Markdown parser and converter, performed insufficient namespace validation of Rouge syntax highlighting formatters.

For the stable distribution (buster), this problem has been fixed in version 1.17.0-1+deb10u2.

We recommend that you upgrade your ruby-kramdown packages.

For the detailed security status of ruby-kramdown please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ruby-kramdown