Bug 1055912 (CVE-2017-13692) - VUL-0: CVE-2017-13692: tidy: Segfault due to out-of-bounds read in ISURLCodePoint function
Summary: VUL-0: CVE-2017-13692: tidy: Segfault due to out-of-bounds read in ISURLCodeP...
Status: RESOLVED FIXED
Alias: CVE-2017-13692
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 42.2
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Adam Majer
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/191008/
Whiteboard: CVSSv2:SUSE:CVE-2017-13692:2.1:(AV:L...
Keywords:
Depends on:
Blocks:
 
Reported: 2017-08-28 11:30 UTC by Marcus Meissner
Modified: 2017-10-09 07:57 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-08-28 11:30:27 UTC
rh#1485857

In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause
a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM
argument.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1485857
https://github.com/htacg/tidy-html5/issues/588
Comment 2 Marcus Meissner 2017-08-28 14:57:27 UTC
I requested the still private testcase, and our newest 5.4 does not seem to be affected.
Comment 4 Johannes Segitz 2017-10-06 11:21:12 UTC
not affected, we can close this one
Comment 5 Marcus Meissner 2017-10-09 07:57:37 UTC
not affected.