Red Hat Bugzilla – Bug 1485857
CVE-2017-13692 tidy: Segfault due to out-of-bounds read in ISURLCodePoint function
Last modified: 2017-08-28 05:51:01 EDT
In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM argument. Upstream bug: https://github.com/htacg/tidy-html5/issues/588
Created tidy tracking bugs for this issue: Affects: epel-7 [bug 1485858] Affects: fedora-all [bug 1485859]