NA

CVE-2023-22483

Published: 23/01/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions before 0.29.0.gfm.7 are subject to several polynomial time complexity issues in cmark-gfm that may lead to unbounded resource exhaustion and subsequent denial of service. Various commands, when piped to cmark-gfm with large values, cause the running time to increase quadratically. These vulnerabilities have been patched in version 0.29.0.gfm.7.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

github cmark-gfm

Vendor Advisories

Debian Bug report logs - #1033110 cmark-gfm: CVE-2023-22483 CVE-2023-22484 CVE-2023-22485 CVE-2023-22486 Package: src:cmark-gfm; Maintainer for src:cmark-gfm is Keith Packard <keithp@keithpcom>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 17 Mar 2023 13:54:04 UTC Severity: important Tags: security, u ...