Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 571872 - <app-text/tidy-html5-5.2.0: use-after-free
Summary: <app-text/tidy-html5-5.2.0: use-after-free
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-01-14 10:19 UTC by Agostino Sarubbo
Modified: 2017-03-02 18:35 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-01-14 10:19:06 UTC
From ${URL} :

A use-after-free was discovered in tidy-html5 (5.1.25) using afl. Technical
details are available here:

https://github.com/htacg/tidy-html5/issues/341



@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Patrice Clement gentoo-dev 2016-01-20 08:57:30 UTC
This issue is being worked on by upstream. I asked for an ETA but no answer so far.

https://github.com/htacg/tidy-html5/issues/341#issuecomment-172794323
Comment 2 Agostino Sarubbo gentoo-dev 2016-02-12 08:33:00 UTC
fixed here:
https://github.com/htacg/tidy-html5/pull/368
Comment 3 Patrice Clement gentoo-dev 2016-03-07 08:46:28 UTC
Fix is in place but in the master branch. However, master is already at 5.1.45:
https://github.com/htacg/tidy-html5/commit/b2c591c138a51b605fb5d82a02c24faf986701ed

and I'm not seeing a new release tag as of now, the latest is still .25 on github :/ I'll revisit this bug in a couple of weeks.
Comment 4 Hanno Böck gentoo-dev 2017-03-02 18:01:47 UTC
This looks obsolete, as this fix should be in 5.2.0, which is currently the only version in the tree. (However 5.4.0, which has just been released, fixes another memory safety issue, see #611424)
Comment 5 Thomas Deutschmann (RETIRED) gentoo-dev 2017-03-02 18:35:18 UTC
Confirmed, patch is in 5.2.0. Repository is clean. Package has no stable ebuild, all done.