Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 744217 (CVE-2020-25821) - app-text/peg-markdown: Null pointer dereference (CVE-2020-25821)
Summary: app-text/peg-markdown: Null pointer dereference (CVE-2020-25821)
Status: RESOLVED FIXED
Alias: CVE-2020-25821
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Deadline: 2021-01-17
Assignee: Gentoo Security
URL:
Whiteboard: ~3 [noglsa]
Keywords: PMASKED
Depends on:
Blocks:
 
Reported: 2020-09-23 04:51 UTC by Sam James
Modified: 2021-01-19 15:44 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-09-23 04:51:36 UTC
Description:
“** UNSUPPORTED WHEN ASSIGNED ** peg-markdown 0.4.14 has a NULL pointer dereference in process_raw_blocks in markdown_lib.c. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.”

Bug: https://github.com/jgm/peg-markdown/issues/43
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-10-04 03:10:52 UTC
Should probably just treeclean. Unmaintained, no revdeps in Gentoo, blocks removal of htmltidy (bug 671440).
Comment 2 Larry the Git Cow gentoo-dev 2020-12-18 09:00:39 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=69fe558b86abe606ab0141384bc96e12dc56232e

commit 69fe558b86abe606ab0141384bc96e12dc56232e
Author:     Michał Górny <mgorny@gentoo.org>
AuthorDate: 2020-12-18 08:44:22 +0000
Commit:     Michał Górny <mgorny@gentoo.org>
CommitDate: 2020-12-18 09:00:04 +0000

    package.mask: Last rite app-text/peg-markdown
    
    Bug: https://bugs.gentoo.org/744217
    Signed-off-by: Michał Górny <mgorny@gentoo.org>

 profiles/package.mask | 5 +++++
 1 file changed, 5 insertions(+)
Comment 3 Larry the Git Cow gentoo-dev 2021-01-19 08:39:21 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=babc185408a7f0c284c2465c9615db0310653fed

commit babc185408a7f0c284c2465c9615db0310653fed
Author:     Michał Górny <mgorny@gentoo.org>
AuthorDate: 2021-01-19 08:36:37 +0000
Commit:     Michał Górny <mgorny@gentoo.org>
CommitDate: 2021-01-19 08:39:08 +0000

    app-text/peg-markdown: Remove last-rited pkg
    
    Bug: https://bugs.gentoo.org/744217
    Signed-off-by: Michał Górny <mgorny@gentoo.org>

 app-text/peg-markdown/Manifest                   |  1 -
 app-text/peg-markdown/metadata.xml               |  8 -----
 app-text/peg-markdown/peg-markdown-0.4.14.ebuild | 41 ------------------------
 profiles/package.mask                            |  5 ---
 4 files changed, 55 deletions(-)