Security Advisory

CVE-2017-17497

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-12-10 22:00:00
Last updated 2024-08-05 20:51:31
Assigner mitre
State PUBLISHED

Description

In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the loop without validating the new value.