A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAlloc of the file src/alloc.c. The manipulation leads to memory leak. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
https://vuldb.com/?id.313614 | technical description vdb entry |
https://vuldb.com/?ctiid.313614 | permissions required signature |
https://vuldb.com/?submit.601009 | third party advisory |
https://github.com/htacg/tidy-html5/issues/1152 | issue tracking |
https://github.com/user-attachments/files/20438303/tidy-html5_crash_3.txt | exploit |