golang-github-cpuguy83-md2man-2.0.2-4.el9

エラータID: AXSA:2023-5357:01

Release date: 
Tuesday, May 16, 2023 - 07:13
Subject: 
golang-github-cpuguy83-md2man-2.0.2-4.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

go-md2man converts markdown into roff (man pages).

Security Fix(es):

* golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise
Linux 9.2 Release Notes linked from the References section.

CVE-2022-41715
Programs which compile regular expressions from untrusted sources may be
vulnerable to memory exhaustion or denial of service. The parsed regexp
representation is linear in the size of the input, but in some cases the
constant factor can be as high as 40,000, making relatively small regexps
consume much larger amounts of memory. After fix, each regexp being parsed is
limited to a 256 MB memory footprint. Regular expressions whose representation
would use more space than that are rejected. Normal use of regular expressions
is unaffected.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. golang-github-cpuguy83-md2man-2.0.2-4.el9.src.rpm
    MD5: 61c4b1a1173b3ebd66265c3e49876447
    SHA-256: 66bcd9b91401994662512c12e5697e207e331a6aabd9c33b0049c2e6dad6c464
    Size: 75.35 kB

Asianux Server 9 for x86_64
  1. golang-github-cpuguy83-md2man-2.0.2-4.el9.x86_64.rpm
    MD5: 39b04c0ac6ac94844914132ef01f1b83
    SHA-256: 73486693f6ebbf28e23aecaacaa5f58cb86beee3c4f8152438033fd7a30e38bb
    Size: 750.92 kB