Bug 16255 - ruby-redcarpet new security issue CVE-2015-5147
Summary: ruby-redcarpet new security issue CVE-2015-5147
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Pascal Terjan
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-06-30 18:54 CEST by David Walser
Modified: 2015-09-02 18:44 CEST (History)
1 user (show)

See Also:
Source RPM: ruby-redcarpet-3.0.0-1.1.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2015-06-30 18:54:21 CEST
A CVE has been assigned for a security issue fixed in redcarpet 3.3.2:
http://openwall.com/lists/oss-security/2015/06/30/10

The commit to fix it is linked in the message above.

Reproducible: 

Steps to Reproduce:
David Walser 2015-06-30 18:54:28 CEST

CC: (none) => mageia

Comment 1 David Walser 2015-09-02 18:44:45 CEST
Affected code appears to not be present in 3.0.0.  Closing as INVALID.

Status: NEW => RESOLVED
Resolution: (none) => INVALID


Note You need to log in before you can comment on or make changes to this bug.