File _patchinfo of Package patchinfo.482
<patchinfo incident="482">
<issue id="933588" tracker="bnc">VUL-1: CVE-2015-5522,CVE-2015-5523: tidy: Heap-based buffer-overflow in tidy/libtidy</issue>
<issue tracker="bnc" id="903962">tidy but no libtidy-devel</issue>
<issue id="CVE-2015-5523" tracker="cve" />
<issue id="CVE-2015-5522" tracker="cve" />
<category>security</category>
<rating>low</rating>
<packager>leonardocf</packager>
<description>
This update fixes two heap-based buffer overflows in tidy/libtidy. These vulnerabilities
could allow remote attackers to cause a denial of service (crash) via vectors involving
a command character in an href. (CVE-2015-5522, CVE-2015-5523)
</description>
<summary>Security update for tidy</summary>
</patchinfo>