Denial of Service Vulnerability in Tidy by HTACG
CVE-2017-17497
7.5HIGH
What is CVE-2017-17497?
In Tidy version 5.7.0, a vulnerability exists in the prvTidyTidyMetaCharset function located in clean.c. This flaw enables attackers to exploit the processing of 'children of the head', leading to a denial of service due to a segmentation fault. The issue arises because the currentNode variable is modified within a loop without proper validation of its new value, creating a pathway for potential crashes and service disruptions.
