Publishing details

Changelog

tidy-html5 (2:5.6.0-11ubuntu0.23.10.1) mantic-security; urgency=medium

  * SECURITY UPDATE: arbitrary code exec via recursive parsing
    - debian/patches/CVE-2021-33391-pre1.patch: introduce stack functions
      in src/lexer.c, src/lexer.h.
    - debian/patches/CVE-2021-33391.patch: refactor the recursion into a
      loop with a heap-based stack in src/gdoc.c.
    - CVE-2021-33391

 -- Marc Deslauriers <email address hidden>  Fri, 10 Nov 2023 10:57:54 +0200

Available diffs

Builds

Built packages

Package files