This update fixes two heap-based buffer overflows in tidy/libtidy. These vulnerabilities could allow remote attackers to cause a denial of service (crash) via vectors involving a command character in an href. (CVE-2015-5522, CVE-2015-5523)
{ "binaries": [ { "libtidy-0_99-0": "1.0.20100204cvs-25.3", "libtidy-0_99-0-devel": "1.0.20100204cvs-25.3", "tidy": "1.0.20100204cvs-25.3" } ] }
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:1513-1.json"