CVE-2017-17497
10.12.2017, 22:29
In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the loop without validating the new value.Enginsight
| Vendor | Product | Version |
|---|---|---|
| htacg | tidy | 5.7.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| tidy |
| ||||||||||||||||||||||
| tidy-html5 |
|
Common Weakness Enumeration