CVE-2017-13692: Input Validation
Published Aug 25, 2017
·Updated
In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM argument.
Affected Software
1 affected component
HTACG Tidy=5.5.31
Remediation
Patch Available
Event History
Aug 25, 2017
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13692?
CVE-2017-13692 has a severity rating that could be classified as moderate due to its potential to cause denial of service.
2
How do I fix CVE-2017-13692?
To fix CVE-2017-13692, upgrade Tidy to a version later than 5.5.31 where the vulnerability is patched.
3
What causes the denial of service in CVE-2017-13692?
The denial of service in CVE-2017-13692 is caused by a segmentation fault triggered by an invalid ISALNUM argument in the IsURLCodePoint function.
4
Which software versions are affected by CVE-2017-13692?
CVE-2017-13692 specifically affects Tidy version 5.5.31.
5
Is CVE-2017-13692 exploitable remotely?
CVE-2017-13692 can be exploited remotely if an attacker can manipulate input processed by the affected Tidy version.