Opened 4 months ago

Closed 4 months ago

#23326 closed enhancement (fixed)

HTML-Parser-3.85 (Perl module)

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version.

Change History (4)

comment:1 by Douglas R. Reno, 4 months ago

Priority: normal → elevated

Fixes CVE-2026-8829. I'm hoping for more details from the CPAN security list shortly.

comment:2 by Joe Locash, 4 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 4 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new
3.85      2026-05-19
    - Replace deprecated uvuni_to_utf8() with uvchr_to_utf8() (GH#50)
      (GitHub Copilot, reported by James E Keenan)

3.84      2026-05-19
    - Fix heap-use-after-free in _decode_entities (CVE-2026-8829) (GH#56)
      (Paul Johnson)

Fixed at a9f26807d6. Leaving open for SA.

comment:4 by Douglas R. Reno, 4 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-102 issued

Note: See TracTickets for help on using tickets.