CVE-2017-17497
7.5
HIGH
CVSS 3.1
EPSS 1.4%
Description
In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the loop without validating the new value.
How to fix CVE-2017-17497
To remediate CVE-2017-17497, upgrade the affected package to a fixed version below.
- Debian/tidy-html5—upgrade to 2:5.6.0-3 or later
Is CVE-2017-17497 being exploited?
Low — EPSS is 1.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2:5.6.0-3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |