Vulnerability Details CVE-2023-22485
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior 0.29.0.gfm.7, a crafted markdown document can trigger an out-of-bounds read in the `validate_protocol` function. We believe this bug is harmless in practice, because the out-of-bounds read accesses `malloc` metadata without causing any visible damage.This vulnerability has been patched in 0.29.0.gfm.7.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.4%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2023-22485
-
cpe:2.3:a:github:cmark-gfm:-
-
cpe:2.3:a:github:cmark-gfm:0.27.1.gfm.0
-
cpe:2.3:a:github:cmark-gfm:0.27.1.gfm.1
-
cpe:2.3:a:github:cmark-gfm:0.27.1.gfm.2
-
cpe:2.3:a:github:cmark-gfm:0.27.1.gfm.3
-
cpe:2.3:a:github:cmark-gfm:0.27.1.gfm.4
-
cpe:2.3:a:github:cmark-gfm:0.28.0.gfm.10
-
cpe:2.3:a:github:cmark-gfm:0.28.0.gfm.11
-
cpe:2.3:a:github:cmark-gfm:0.28.0.gfm.5
-
cpe:2.3:a:github:cmark-gfm:0.28.0.gfm.6
-
cpe:2.3:a:github:cmark-gfm:0.28.0.gfm.7
-
cpe:2.3:a:github:cmark-gfm:0.28.0.gfm.8
-
cpe:2.3:a:github:cmark-gfm:0.28.0.gfm.9
-
cpe:2.3:a:github:cmark-gfm:0.28.3.gfm.12
-
cpe:2.3:a:github:cmark-gfm:0.28.3.gfm.13
-
cpe:2.3:a:github:cmark-gfm:0.28.3.gfm.14
-
cpe:2.3:a:github:cmark-gfm:0.28.3.gfm.15
-
cpe:2.3:a:github:cmark-gfm:0.28.3.gfm.16
-
cpe:2.3:a:github:cmark-gfm:0.28.3.gfm.17
-
cpe:2.3:a:github:cmark-gfm:0.28.3.gfm.18
-
cpe:2.3:a:github:cmark-gfm:0.28.3.gfm.19
-
cpe:2.3:a:github:cmark-gfm:0.28.3.gfm.20
-
cpe:2.3:a:github:cmark-gfm:0.28.3.gfm.21
-
cpe:2.3:a:github:cmark-gfm:0.29.0.gfm.0
-
cpe:2.3:a:github:cmark-gfm:0.29.0.gfm.1
-
cpe:2.3:a:github:cmark-gfm:0.29.0.gfm.2
-
cpe:2.3:a:github:cmark-gfm:0.29.0.gfm.3
-
cpe:2.3:a:github:cmark-gfm:0.29.0.gfm.4
-
cpe:2.3:a:github:cmark-gfm:0.29.0.gfm.5
-
cpe:2.3:a:github:cmark-gfm:0.29.0.gfm.6