Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < 5ced426d97ce84299ecfcc7bd8b38f975fd11089 |