Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5523

Опубликовано: 03 июн. 2015
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.

It was discovered that tidy did not properly process certain character sequences. By tricking an application that is using tidy into processing a specially crafted HTML document, a remote attacker could exploit this flaw to cause a crash or, possibly, execute arbitrary code with the privileges of the affected application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6tidyWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1228297tidy: heap buffer overflow in ParseValue()

EPSS

Процентиль: 89%
0.05027
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.

nvd
больше 10 лет назад

The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.

debian
больше 10 лет назад

The ParseValue function in lexer.c in tidy before 4.9.31 allows remote ...

github
больше 3 лет назад

The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.

suse-cvrf
больше 10 лет назад

Security update for tidy

EPSS

Процентиль: 89%
0.05027
Низкий

5.1 Medium

CVSS2