CVE-2015-5522
published 2015-08-11CVE-2015-5522: Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors…
PriorityP434medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.66%
90.7th percentile
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_9 | — | — |
| apple | iphone_os | <= 8.2 | — |
| apple | mac_os_x | <= 10.6.8 | — |
| apple | os_x_el_capitan_v10.11 | — | — |
| apple | watchos | <= 1.0.1 | — |
| apple | watchos_2 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| htacg | tidy | <= 4.9.30 | — |
| htacg | tidy | >= 0 < 20091223cvs-1.2ubuntu1.1 | 20091223cvs-1.2ubuntu1.1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wp28-phrj-p6rh: Heap-based buffer overflow in the ParseValue function in lexer
ghsa_unreviewed·2022-05-17
CVE-2015-5522 [MEDIUM] CWE-119 GHSA-wp28-phrj-p6rh: Heap-based buffer overflow in the ParseValue function in lexer
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
OSV
CVE-2015-5522: Heap-based buffer overflow in the ParseValue function in lexer
osv·2015-07-16·CVSS 6.8
CVE-2015-5522 [MEDIUM] CVE-2015-5522: Heap-based buffer overflow in the ParseValue function in lexer
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
Ubuntu
HTML Tidy vulnerabilities
vendor_ubuntu·2015-07-29
CVE-2015-5522 HTML Tidy vulnerabilities
Title: HTML Tidy vulnerabilities
Summary: HTML Tidy could be made to crash or run programs if it processed specially
crafted data.
Fernando Muñoz discovered that HTML Tidy incorrectly handled memory. If a
user or automated system were tricked into processing specially crafted
data, applications linked against HTML Tidy could be made to crash, leading
to a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tidy: heap buffer overflow in ParseValue()
vendor_redhat·2015-06-03·CVSS 6.8
CVE-2015-5522 [MEDIUM] CWE-122 tidy: heap buffer overflow in ParseValue()
tidy: heap buffer overflow in ParseValue()
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
It was discovered that tidy did not properly process certain character sequences. By tricking an application that is using tidy into processing a specially crafted HTML document, a remote attacker could exploit this flaw to cause a crash or, possibly, execute arbitrary code with the privileges of the affected application.
Package: tidy (Red Hat Enterprise Linux 6) - Will not fix
Apple
CVE-2015-5522: watchOS 2
vendor_apple·CVSS 6.8
CVE-2015-5522 [MEDIUM] CVE-2015-5522: watchOS 2
Apple Security Update: About the security content of watchOS 2
Product: watchOS 2
CVE: CVE-2015-5522
Component: CVE-ID
Apple
CVE-2015-5522: iOS 9
vendor_apple·CVSS 6.8
CVE-2015-5522 [MEDIUM] CVE-2015-5522: iOS 9
Apple Security Update: About the security content of iOS 9
Product: iOS 9
CVE: CVE-2015-5522
Component: CVE-ID
Apple
CVE-2015-5522: OS X El Capitan v10.11
vendor_apple·CVSS 6.8
CVE-2015-5522 [MEDIUM] CVE-2015-5522: OS X El Capitan v10.11
Apple Security Update: About the security content of OS X El Capitan v10.11
Product: OS X El Capitan v10.11
CVE: CVE-2015-5522
Component: CVE-ID
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://www.debian.org/security/2015/dsa-3309http://www.openwall.com/lists/oss-security/2015/06/04/2http://www.openwall.com/lists/oss-security/2015/07/13/7http://www.openwall.com/lists/oss-security/2015/07/15/3http://www.securityfocus.com/bid/75037http://www.securitytracker.com/id/1033703http://www.ubuntu.com/usn/USN-2695-1https://github.com/htacg/tidy-html5/issues/217https://support.apple.com/HT205212https://support.apple.com/HT205213https://support.apple.com/HT205267http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://www.debian.org/security/2015/dsa-3309http://www.openwall.com/lists/oss-security/2015/06/04/2http://www.openwall.com/lists/oss-security/2015/07/13/7http://www.openwall.com/lists/oss-security/2015/07/15/3http://www.securityfocus.com/bid/75037http://www.securitytracker.com/id/1033703http://www.ubuntu.com/usn/USN-2695-1https://github.com/htacg/tidy-html5/issues/217https://support.apple.com/HT205212https://support.apple.com/HT205213https://support.apple.com/HT205267
2015-08-11
Published