CVE-2025-6497

Publication date 23 June 2025

Last updated 13 August 2025


Ubuntu priority

Cvss 3 Severity Score

3.3 · Low

Score breakdown

A vulnerability was found in HTACG tidy-html5 5.8.0. It has been rated as problematic. This issue affects the function prvTidyParseNamespace of the file src/parser.c. The manipulation leads to reachable assertion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

Read the notes from the security team

Status

Package Ubuntu Release Status
tidy-html5 25.04 plucky
Vulnerable, fix deferred
24.10 oracular Ignored end of life, was deferred [2025-08-13]
24.04 LTS noble
Vulnerable, fix deferred
22.04 LTS jammy
Vulnerable, fix deferred
20.04 LTS focal
Vulnerable, fix deferred
18.04 LTS bionic
Vulnerable, fix deferred

Notes


mdeslaur

as of 2025-08-13, there is no upstream fix for this issue

Severity score breakdown

Parameter Value
Base score 3.3 · Low
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact Low
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L