This update fixes two heap-based buffer overflows in tidy/libtidy. These vulnerabilities could allow remote attackers to cause a denial of service (crash) via vectors involving a command character in an href. (CVE-2015-5522, CVE-2015-5523)
{ "binaries": [ { "libtidy": "1.0-37.1" } ] }
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:1525-1.json"
{ "binaries": [ { "libtidy": "1.0-37.1", "libtidy-devel": "1.0-37.1", "tidy": "1.0-37.1" } ] }