Bug 2175697 (CVE-2023-26302)

Summary: CVE-2023-26302 markdown-it-py: Denial of service in the command line interface due to invalid UTF-8 characters as input.
Product: [Other] Security Response Reporter: Vipul Nair <vinair>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: adudiak, bcoca, cwelton, davidn, epacific, jcammara, jhardy, jneedle, jobarker, kshier, mabashia, maxwell, osapryki, simaishi, smcdonal, stcannon, teagle, tfister, yguenane, zsadeh
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: markdown-it-py 2.2.0 Doc Type: If docs needed, set a value
Doc Text:
A denial of service vulnerability exists in markdown-it-py.An attacker could craft a payload with invalid UTF-8 characters as input to cause a crash thereby affecting the availability
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2175701, 2175702, 2177154    
Bug Blocks: 2172788    

Description Vipul Nair 2023-03-06 11:09:53 UTC
Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input.

https://github.com/executablebooks/markdown-it-py/commit/53ca3e9c2b9e9b295f6abf7f4ad2730a9b70f68c

Comment 1 Vipul Nair 2023-03-06 11:17:53 UTC
Created ansible-lint tracking bugs for this issue:

Affects: fedora-all [bug 2175701]


Created python-ansible-compat tracking bugs for this issue:

Affects: fedora-all [bug 2175702]

Comment 2 Maxwell G 2023-03-06 17:39:38 UTC
Why were bugs opened against ansible-lint and python-ansible-compat when this is a problem with python-markdown-it-py? No bugs were opened against python-markdown-it-py.

Comment 3 Vipul Nair 2023-03-10 08:18:35 UTC
you are right,fixed it.Thanks

Comment 4 Vipul Nair 2023-03-10 08:20:00 UTC
Created python-markdown-it-py tracking bugs for this issue:

Affects: fedora-all [bug 2177154]