• 公告ID (KylinSec-SA-2024-1019)

摘要:

tidy security update

安全等级: Critical

公告ID: KylinSec-SA-2024-1019

发布日期: 2024年1月5日

关联CVE: CVE-2021-33391  

  • 详细介绍

1. 漏洞描述

   

When editing HTML it's easy to make mistakes. Wouldn't it be nice if there was a simple way to fix these mistakes automatically and tidy up sloppy editing into nicely laid out markup? Well now there is! Dave Raggett's HTML TIDY is a free utility for doing just that. It also works great on the atrociously hard to read markup generated by specialized HTML editors and conversion tools, and can help you identify where you need to pay further attention on making your pages more accessible to people with disabilities.

Security Fix(es):

An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.(CVE-2021-33391)

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2021-33391 KY3.4-4A tidy Fixed
CVE-2021-33391 KY3.4-5A tidy Fixed
CVE-2021-33391 KY3.5.1 tidy Fixed
CVE-2021-33391 KY3.5.2 tidy Fixed

3. 影响组件

    tidy

4. 修复版本

   

KY3.5.1

软件名称 架构 版本号
tidy-help noarch 5.7.28-2.kb1.ky3_5
tidy x86_64 5.7.28-2.kb1.ky3_5
libtidy x86_64 5.7.28-2.kb1.ky3_5
libtidy-devel x86_64 5.7.28-2.kb1.ky3_5
libtidy-devel aarch64 5.7.28-2.kb1.ky3_5
tidy aarch64 5.7.28-2.kb1.ky3_5
libtidy aarch64 5.7.28-2.kb1.ky3_5

KY3.4-4A

软件名称 架构 版本号
tidy-help noarch 5.6.0-5.kb2.ky3_4
libtidy-devel x86_64 5.6.0-5.kb2.ky3_4
libtidy x86_64 5.6.0-5.kb2.ky3_4
tidy x86_64 5.6.0-5.kb2.ky3_4
libtidy-devel aarch64 5.6.0-5.kb2.ky3_4
libtidy aarch64 5.6.0-5.kb2.ky3_4
tidy aarch64 5.6.0-5.kb2.ky3_4

KY3.4-5A

软件名称 架构 版本号
tidy-help noarch 5.6.0-5.kb2.ky3_4
libtidy-devel x86_64 5.6.0-5.kb2.ky3_4
libtidy x86_64 5.6.0-5.kb2.ky3_4
tidy x86_64 5.6.0-5.kb2.ky3_4
libtidy aarch64 5.6.0-5.kb2.ky3_4
tidy aarch64 5.6.0-5.kb2.ky3_4
libtidy-devel aarch64 5.6.0-5.kb2.ky3_4

KY3.5.2

软件名称 架构 版本号
tidy-help noarch 5.7.28-2.ky3_5
libtidy x86_64 5.7.28-2.ky3_5
tidy x86_64 5.7.28-2.ky3_5
libtidy-devel x86_64 5.7.28-2.ky3_5
libtidy aarch64 5.7.28-2.ky3_5
libtidy-devel aarch64 5.7.28-2.ky3_5
tidy aarch64 5.7.28-2.ky3_5

5. 修复方法


方法一:下载安装包进行升级安装
1、通过下载链接下载需要升级的升级包保存,如 xxx.rpm
2、通过rpm命令升级,如 rpm -Uvh xxx.rpm

方法二:通过软件源进行升级安装
1、保持能够连接上互联网
2、通过yum命令升级指定的包,如 yum install 包名

6. 下载链接

   

KY3.5.1:

x86_64:

     tidy-help   

     tidy   

     libtidy   

     libtidy-devel   

aarch64:

     tidy-help   

     libtidy-devel   

     tidy   

     libtidy   

KY3.4-4A:

x86_64:

     tidy-help   

     libtidy-devel   

     libtidy   

     tidy   

aarch64:

     tidy-help   

     libtidy-devel   

     libtidy   

     tidy   

KY3.4-5A:

x86_64:

     tidy-help   

     libtidy-devel   

     libtidy   

     tidy   

aarch64:

     tidy-help   

     libtidy   

     tidy   

     libtidy-devel   

KY3.5.2:

x86_64:

     tidy-help   

     libtidy   

     tidy   

     libtidy-devel   

aarch64:

     tidy-help   

     libtidy   

     libtidy-devel   

     tidy   

上一篇:KylinSec-SA-2024-1018 下一篇:KylinSec-SA-2024-1020