Lucene search

K
suseSuseOPENSUSE-SU-2021:0451-1
HistoryMar 20, 2021 - 12:00 a.m.

Security update for python-markdown2 (moderate)

2021-03-2000:00:00
lists.opensuse.org
14
python-markdown2
security update
regex dos
xss
opensuse
patch

EPSS

0.003

Percentile

69.8%

An update that solves one vulnerability and has two fixes
is now available.

Description:

This update for python-markdown2 fixes the following issues:

Update to 2.4.0 (boo#1181270):

 - [pull #377] Fixed bug breaking strings elements in metadata lists
 - [pull #380] When rendering fenced code blocks, also add the
   language-LANG class
 - [pull #387] Regex DoS fixes (CVE-2021-26813, boo#1183171)
  • Switch off failing tests (gh#trentm/python-markdown2#388), ignore
    failing test suite.

update to 2.3.9:

 - [pull #335] Added header support for wiki tables
 - [pull #336] Reset _toc when convert is run
 - [pull #353] XSS fix
 - [pull #350] XSS fix
  • Add patch to fix unsanitized input for cross-site scripting (boo#1171379)

This update was imported from the openSUSE:Leap:15.2:Update update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

  • openSUSE Backports SLE-15-SP2:

    zypper in -t patch openSUSE-2021-451=1