{"id":"CVE-2015-5147","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-5147","summary":"redcarpet Buffer Overflow vulnerability","details":"Stack-based buffer overflow in the `header_anchor` function in the HTML renderer in Redcarpet before 3.3.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.","published":"2018-08-15T20:04:30Z","modified":"2024-12-05T05:30:05.129589Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"RubyGems","name":"redcarpet","fixedVersion":"3.3.2"}],"fix":{"url":"https://github.com/vmg/redcarpet/commit/2cee777c1e5babe8a1e2683d31ea75cc4afe55fb","label":"vmg/redcarpet@2cee777"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-5147"},{"type":"WEB","url":"https://github.com/vmg/redcarpet/commit/2cee777c1e5babe8a1e2683d31ea75cc4afe55fb"},{"type":"PACKAGE","url":"https://github.com/vmg/redcarpet"},{"type":"WEB","url":"https://github.com/vmg/redcarpet/blob/master/CHANGELOG.md"},{"type":"WEB","url":"https://web.archive.org/web/20150711061256/http://www.securityfocus.com/bid/75508"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/06/29/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/06/30/10"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:30:05.129589Z"}}