Описание
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| tidy-html5 | fixed | 2:5.8.0-2 | package | |
| tidy-html5 | ignored | bookworm | package | |
| tidy-html5 | no-dsa | bullseye | package | |
| tidy-html5 | no-dsa | buster | package |
Примечания
https://github.com/htacg/tidy-html5/issues/946
https://github.com/htacg/tidy-html5/commit/efa61528aa500a1efbd2768121820742d3bb709b (5.9.8-next)
EPSS
Связанные уязвимости
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
Уязвимость функции CleanNode() компонента gdoc.c инструмента форматирования кода HTML Tidy, позволяющая нарушителю вызвать отказ в обслуживании
EPSS