中危 github cmark-gfm 未加控制的资源消耗(资源穷尽)
CVE编号
CVE-2022-39209利用情况
暂无补丁情况
官方补丁披露时间
2022-09-16漏洞描述
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service. Users may verify the patch by running `python3 -c 'print("
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论