Denial of Service Vulnerability in Tidy by HTACG
CVE-2017-17497

7.5HIGH

Key Information:

Vendor

Htacg

Status
Vendor
CVE Published:
10 December 2017

What is CVE-2017-17497?

In Tidy version 5.7.0, a vulnerability exists in the prvTidyTidyMetaCharset function located in clean.c. This flaw enables attackers to exploit the processing of 'children of the head', leading to a denial of service due to a segmentation fault. The issue arises because the currentNode variable is modified within a loop without proper validation of its new value, creating a pathway for potential crashes and service disruptions.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.