=========================================================================Ubuntu Security Notice USN-2695-1
July 29, 2015

tidy vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

HTML Tidy could be made to crash or run programs if it processed specially
crafted data.

Software Description:
- tidy: HTML syntax checker and reformatter

Details:

Fernando Muñoz discovered that HTML Tidy incorrectly handled memory. If a
user or automated system were tricked into processing specially crafted
data, applications linked against HTML Tidy could be made to crash, leading
to a denial of service, or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  libtidy-0.99-0                  20091223cvs-1.4ubuntu0.1

Ubuntu 14.04 LTS:
  libtidy-0.99-0                  20091223cvs-1.2ubuntu1.1

Ubuntu 12.04 LTS:
  libtidy-0.99-0                  20091223cvs-1ubuntu2.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2695-1
  CVE-2015-5522, CVE-2015-5523

Package Information:
  https://launchpad.net/ubuntu/+source/tidy/20091223cvs-1.4ubuntu0.1
  https://launchpad.net/ubuntu/+source/tidy/20091223cvs-1.2ubuntu1.1
  https://launchpad.net/ubuntu/+source/tidy/20091223cvs-1ubuntu2.1


Ubuntu 2695-1: HTML Tidy vulnerabilities

July 29, 2015
HTML Tidy could be made to crash or run programs if it processed specially crafted data.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: libtidy-0.99-0 20091223cvs-1.4ubuntu0.1 Ubuntu 14.04 LTS: libtidy-0.99-0 20091223cvs-1.2ubuntu1.1 Ubuntu 12.04 LTS: libtidy-0.99-0 20091223cvs-1ubuntu2.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2695-1

CVE-2015-5522, CVE-2015-5523

Severity
July 29, 2015

Package Information

https://launchpad.net/ubuntu/+source/tidy/20091223cvs-1.4ubuntu0.1 https://launchpad.net/ubuntu/+source/tidy/20091223cvs-1.2ubuntu1.1 https://launchpad.net/ubuntu/+source/tidy/20091223cvs-1ubuntu2.1

Related News