MidnightBSD

Advisories for htacg

CVE-2015-5522 MEDIUM

Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
canonical ubuntu_linux 14.04
htacg tidy *
canonical ubuntu_linux 15.04
apple watchos *
debian debian_linux 7.0
apple mac_os_x *
apple iphone_os *
canonical ubuntu_linux 12.04
debian debian_linux 8.0
CVE-2015-5523 MEDIUM

The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
canonical ubuntu_linux 14.04
htacg tidy *
canonical ubuntu_linux 15.04
apple watchos *
apple iphone_os *
apple mac_os_x *
debian debian_linux 7.0
debian debian_linux 8.0
canonical ubuntu_linux 12.04
CVE-2017-13692 MEDIUM

In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
htacg tidy 5.5.31
CVE-2017-17497 MEDIUM

In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the loop without validating the new value.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
htacg tidy 5.7.0