CVE-2017-17497

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
10/12/2017
Last modified:
20/04/2025

Description

In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the loop without validating the new value.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:htacg:tidy:5.7.0:*:*:*:*:*:*:*