First published: Fri Aug 25 2017(Updated: )
In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM argument.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HTACG Tidy | =5.5.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-13692 has a severity rating that could be classified as moderate due to its potential to cause denial of service.
To fix CVE-2017-13692, upgrade Tidy to a version later than 5.5.31 where the vulnerability is patched.
The denial of service in CVE-2017-13692 is caused by a segmentation fault triggered by an invalid ISALNUM argument in the IsURLCodePoint function.
CVE-2017-13692 specifically affects Tidy version 5.5.31.
CVE-2017-13692 can be exploited remotely if an attacker can manipulate input processed by the affected Tidy version.