Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 576870

Summary: <app-text/tidy-html5-5.2.0: infinite loop parsing an html file
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: monsieurp
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://www.openwall.com/lists/oss-security/2016/03/04/2
Whiteboard: ~3 [noglsa]
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2016-03-09 15:20:04 UTC
From ${URL} :

A DoS parsing a html file was discovered in tidy-html5 (affecting 5.1.25
and last revisions) using afl. Technical details are available here:

https://github.com/htacg/tidy-html5/issues/380



@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-06-04 07:35:23 UTC
Issues were resolved in:

https://github.com/htacg/tidy-html5/commit/8a31aad0e35c192bde6fa4c995d96b6eede7ebba

@maintainer, please cleanup the vulnerable version (5.1.9) in tree.
Comment 2 Patrice Clement gentoo-dev 2016-06-06 09:41:41 UTC
commit ec058ac199d3547ef86fc6124b66d6c267094846 (HEAD -> master)
Author:     Patrice Clement <monsieurp@gentoo.org>
AuthorDate: Mon Jun 6 09:13:19 2016 +0000
Commit:     Patrice Clement <monsieurp@gentoo.org>
CommitDate: Mon Jun 6 09:13:19 2016 +0000

app-text/tidy-html5: Clean up vulnerable version.

Gentoo-Bug: https://bugs.gentoo.org/576870
Gentoo-Bug: https://bugs.gentoo.org/576138

Package-Manager: portage-2.2.28

app-text/tidy-html5/Manifest                |  1 -
app-text/tidy-html5/tidy-html5-5.1.9.ebuild | 44 --------------------------------------------
2 files changed, 45 deletions(-)
delete mode 100644 app-text/tidy-html5/tidy-html5-5.1.9.ebuild
Comment 3 Patrice Clement gentoo-dev 2016-06-06 09:43:24 UTC
Please proceed.
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2016-06-06 09:50:21 UTC
Cleanup complete by maintainer.  Unstable, so no GLSA required.