Improper Input Validation Affecting r-cran-commonmark package, versions <1.8.0-1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
1.18% (85th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-RCRANCOMMONMARK-575452
  • published8 Jul 2020
  • disclosed1 Jul 2020

Introduced: 1 Jul 2020

CVE-2020-5238  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade Debian:unstable r-cran-commonmark to version 1.8.0-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream r-cran-commonmark package and not the r-cran-commonmark package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the upstream cmark project. The issue has been fixed in version 0.29.0.gfm.1.

CVSS Scores

version 3.1