La funzione islist in markdown.c in libmarkdown.a in SCONTO 2.2.3a permette attaccanti remoti di causare una negazione di servizio (heap-based buffer di over-read) tramite un file predisposto, come dimostrato da mkd2html. |
https://www.debian.org/security/2018/dsa-4293 https://github.com/Orc/discount/issues/189#issuecomment-392247798 https://lists.debian.org/debian-lts-announce/2018/09/msg00009.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11504 |
Vulnerabilità: CVE-2018-11504
