CVE-2017-17497
10.12.2017, 22:29
In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the loop without validating the new value.Enginsight
Vendor | Product | Version |
---|---|---|
htacg | tidy | 5.7.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
tidy |
| ||||||||||||||||||||||
tidy-html5 |
|
Common Weakness Enumeration