Bugzilla – Bug 1055912
VUL-0: CVE-2017-13692: tidy: Segfault due to out-of-bounds read in ISURLCodePoint function
Last modified: 2017-10-09 07:57:37 UTC
rh#1485857 In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM argument. References: https://bugzilla.redhat.com/show_bug.cgi?id=1485857 https://github.com/htacg/tidy-html5/issues/588
I requested the still private testcase, and our newest 5.4 does not seem to be affected.
not affected, we can close this one
not affected.