Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Fedora Core 11 FEDORA-2009-10329 (python-markdown2)

Information

Severity

Severity

Medium

Family

Family

Fedora Local Security Checks

CVSSv2 Base

CVSSv2 Base

4.3

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

Solution Type

Solution Type

Vendor Patch

Created

Created

14 years ago

Modified

Modified

6 years ago

Summary

The remote host is missing an update to python-markdown2 announced via advisory FEDORA-2009-10329.

Insight

Insight

Update Information: Update from 1.0.1.11 to 1.0.1.15, which fixes some issues, including these two security-related bugs: - [Issue 30] Fix a possible XSS via JavaScript injection in a carefully crafted image reference (usage of double-quotes in the URL). - [Issue 29] Fix security hole in the md5-hashing scheme for handling HTML chunks during processing. See http://code.google.com/p/python-markdown2/source/browse/trunk/CHANGES.txt for the full changelog. ChangeLog: * Thu Oct 8 2009 Thomas Moschny - 1.0.1.15-1 - Update to 1.0.1.15. Fixes three issues, two of them being security-related.

Solution

Solution

Apply the appropriate updates. This update can be installed with the yum update program. Use su -c 'yum update python-markdown2' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/. https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2009-10329