RedCloth: ReDoS Vulnerability — GLSA 202401-14

A denial of service vulnerability has been found in RedCloth.

Affected packages

dev-ruby/redcloth on all architectures
Affected versions < 4.3.2-r5
Unaffected versions >= 4.3.2-r5

Background

RedCloth is a module for using Textile in Ruby

Description

A vulnerability has been discovered in RedCloth. Please review the CVE identifier referenced below for details.

Impact

RedCloth is vulnerable to a regular expression denial of service ("ReDoS") attack via the sanitize_html function.

Workaround

There is no known workaround at this time.

Resolution

All RedCloth users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=dev-ruby/redcloth-4.3.2-r5"
 

References

Release date
January 10, 2024

Latest revision
January 10, 2024: 1

Severity
low

Exploitable
remote

Bugzilla entries