perl-HTML-Gumbo-0.19-1.fc44
- perl-HTML-Gumbo-0.19-1.fc44
This package provides the Perl module HTML::Gumbo. Versions before 0.19 disclose heap memory via type confusion.
Support for the <template> element was added to libgumbo 0.10.0 in 2015, but the walk_tree function in lib/HTML/Gumbo.xs was not updated to support it. The element was treated as a text-node, where strlen() over-reads the heap block that the pointer addresses.</template>