Debian Security Advisory

DSA-4890-1 ruby-kramdown -- security update

Date Reported:
12 Apr 2021
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 985569.
In Mitre's CVE dictionary: CVE-2021-28834.
More information:

Stan Hu discovered that kramdown, a pure Ruby Markdown parser and converter, performed insufficient namespace validation of Rouge syntax highlighting formatters.

For the stable distribution (buster), this problem has been fixed in version 1.17.0-1+deb10u2.

We recommend that you upgrade your ruby-kramdown packages.

For the detailed security status of ruby-kramdown please refer to its security tracker page at: