oss-sec mailing list archives

Re: use-after-free in tidy-html5


From: Gustavo Grieco <gustavo.grieco () gmail com>
Date: Mon, 25 Jan 2016 10:57:53 -0300

Hi,

The tidy-html5 developers are still not sure how to fix this security
issue. Any feedback is appreciated.

Thanks!

2016-01-03 20:24 GMT-03:00 Gustavo Grieco <gustavo.grieco () gmail com>:

A use-after-free was discovered in tidy-html5 (5.1.25) using afl.
Technical details are available here:

https://github.com/htacg/tidy-html5/issues/341

Regards,
Gus


Current thread: