Lucene search

K
rockyRockylinux Product ErrataRLSA-2022:5597
HistoryJul 18, 2022 - 12:00 a.m.

pandoc security update

2022-07-1800:00:00
Rockylinux Product Errata
errata.rockylinux.org
15
pandoc
security update
rocky linux 8
cve-2022-24724
integer overflow
cmark-gfm
heap memory corruption
cvss score
references section

EPSS

0.065

Percentile

93.7%

An update for pandoc is now available for Rocky Linux 8.
Rocky Enterprise Software Foundation Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Pandoc is a markdown/markup conversion tool. The version of pandoc in RHEL 8 CRB uses cmark-gfm (GitHub's extended version of the C reference implementation of CommonMark) for parts of its conversion. The update, fixes CVE-2022-24724: an integer overflow in cmark-gfm's table row parsing which may lead to heap memory corruption when parsing tables with more than UINT16_MAX columns.
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.