CVE-2024-22051
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.
Affected (3)
Products: Github: Cmark Gfm · Gjtorikian: Commonmarker
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 0.28.3.gfm.21 | |
| Before 0.23.4 |
References (10)
Source: disclosure@vulncheck.com
Third Party Advisory
Source: disclosure@vulncheck.com
Not Applicable
Source: disclosure@vulncheck.com
Patch
Source: disclosure@vulncheck.com
Vendor Advisory
Source: disclosure@vulncheck.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.