4
CVSSv2

CVE-2020-5238

Published: 01/07/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the upstream cmark project. The issue has been fixed in version 0.29.0.gfm.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

github flavored markdown project github flavored markdown

fedoraproject fedora 31

fedoraproject fedora 32

fedoraproject fedora 33

Vendor Advisories

Debian Bug report logs - #965980 CVE-2020-5238 Package: r-cran-commonmark; Maintainer for r-cran-commonmark is Debian R Packages Maintainers <r-pkg-team@alioth-listsdebiannet>; Source for r-cran-commonmark is src:r-cran-commonmark (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 21 ...