-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4293-1 secur...@debian.org https://www.debian.org/security/ Alessandro Ghedini September 14, 2018 https://www.debian.org/security/faq - -------------------------------------------------------------------------
Package : discount CVE ID : CVE-2018-11468 CVE-2018-11503 CVE-2018-11504 CVE-2018-12495 Debian Bug : 901912 Several heap buffer overflows were found in discount, an implementation of the Markdown markup language, that could be triggered witth specially crafted Markdown data and would cause discount to read past the end of internal buffers. For the stable distribution (stretch), these problems have been fixed in version 2.2.2-1+deb9u1. We recommend that you upgrade your discount packages. For the detailed security status of discount please refer to its security tracker page at: https://security-tracker.debian.org/tracker/discount Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-annou...@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBsId305pBx+F583DbwzL4CFiRygFAlucFr4ACgkQbwzL4CFi RygF7A//U2mkexpsLmHVfGauN46rZANivJLenTCO3kX9EQ2EV2JctBZLhlnRZFUl RAK07NW/7CoZb0MRiVibUA53QRydC/OP1V7yjwSeFqadYF2+tS9ImVJYCGzeXT6W ollF0e6Sq9BA3adHm8daHCaPWWU3k1BwrjivEUt1Wv6M6NKzAI+LpIKgqW32kbs7 UdwFhQhwGrvfUYgkTEtX1iOlfxdncNceOD27kjTIFINJqg9z5HcOpAtyDWoz/GmI zQ/jEyAvI4nbNYpqzWPh0GNSDRsFvIt+IKS0Swe8lWed7ZhV7+DH4S3zd8f78YwY 5K3bYaHZCJL9ku8p5IJcWD/A/Cn9pF1So90n0//oOhREUwM3djSJzgR+CuFFLtDf RODNcaKjKHFk7ZRK/FUXNpHNDz8tIUJbQQwA/Juq24eJk4UTxybrWwhGAOXDqsXk tgqdtSQA3z/XNGNInTIjPXEU6MmKJnYSfwYl6ZAteXgSKs90wFAOTMw5TpOL0wXS ESh8TgqdhuaRwnRCPLQqsxQ/q97RpclvUSd79XXFZfuAuaUhB02/1I4Sk6W+qIzg 9LiyK0xj6mxSMZGSL7kN6Fh3yP17n5/Le3g7fTibvApANDmefwfrUegugGNBMZhN 99e/TQmnQhxAHHPh+vPCLyiADVTe3MrjUzjpXzlxkoIywO3CNAY= =Xd5u -----END PGP SIGNATURE-----