Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 576138 - <app-text/tidy-html5-5.2.0: Out-of-bounds heap read in TextEndsWithNewline
Summary: <app-text/tidy-html5-5.2.0: Out-of-bounds heap read in TextEndsWithNewline
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-03-01 17:41 UTC by Agostino Sarubbo
Modified: 2016-06-06 09:49 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-03-01 17:41:18 UTC
From ${URL} :

An out-of-bounds heap read was found in tidy caused by specially crafted input.

Upstream bug:

https://github.com/htacg/tidy-html5/issues/379

Public via:

http://seclists.org/oss-sec/2016/q1/457


@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-06-04 07:36:35 UTC
Issues were resolved in:

https://github.com/htacg/tidy-html5/commit/8a31aad0e35c192bde6fa4c995d96b6eede7ebba

@maintainer, please cleanup the vulnerable version (5.1.9) in tree.
Comment 2 Patrice Clement gentoo-dev 2016-06-06 09:41:44 UTC
commit ec058ac199d3547ef86fc6124b66d6c267094846 (HEAD -> master)
Author:     Patrice Clement <monsieurp@gentoo.org>
AuthorDate: Mon Jun 6 09:13:19 2016 +0000
Commit:     Patrice Clement <monsieurp@gentoo.org>
CommitDate: Mon Jun 6 09:13:19 2016 +0000

app-text/tidy-html5: Clean up vulnerable version.

Gentoo-Bug: https://bugs.gentoo.org/576870
Gentoo-Bug: https://bugs.gentoo.org/576138

Package-Manager: portage-2.2.28

app-text/tidy-html5/Manifest                |  1 -
app-text/tidy-html5/tidy-html5-5.1.9.ebuild | 44 --------------------------------------------
2 files changed, 45 deletions(-)
delete mode 100644 app-text/tidy-html5/tidy-html5-5.1.9.ebuild
Comment 3 Patrice Clement gentoo-dev 2016-06-06 09:43:15 UTC
Please proceed.
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2016-06-06 09:49:39 UTC
Cleanup complete by maintainer.  Unstable, so no GLSA is required.