UbuntuUpdates.org

Package "tidy"

Name: tidy

Description:

HTML/XML syntax checker and reformatter

Latest version: 2:5.6.0-11ubuntu0.23.10.1
Release: mantic (23.10)
Level: security
Repository: universe
Head package: tidy-html5
Homepage: https://www.html-tidy.org/

Links


Download "tidy"


Other versions of "tidy" in Mantic

Repository Area Version
base universe 2:5.6.0-11build2
updates universe 2:5.6.0-11ubuntu0.23.10.1

Changelog

Version: 2:5.6.0-11ubuntu0.23.10.1 2023-11-15 16:10:16 UTC

  tidy-html5 (2:5.6.0-11ubuntu0.23.10.1) mantic-security; urgency=medium

  * SECURITY UPDATE: arbitrary code exec via recursive parsing
    - debian/patches/CVE-2021-33391-pre1.patch: introduce stack functions
      in src/lexer.c, src/lexer.h.
    - debian/patches/CVE-2021-33391.patch: refactor the recursion into a
      loop with a heap-based stack in src/gdoc.c.
    - CVE-2021-33391

 -- Marc Deslauriers <email address hidden> Fri, 10 Nov 2023 10:57:54 +0200

CVE-2021-33391 An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.



About   -   Send Feedback to @ubuntu_updates