CVE-2021-23180NULL Pointer Dereference in Project Htmldoc

Severity
7.8HIGHNVD
EPSS
0.3%
top 48.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 2
Latest updateMar 4

Description

A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debianhtmldoc_project/htmldoc< 1.9.11-4+3
CVEListV5htmldoc_project/htmldocFixed in htmldoc v1.9.12 and above.

Patches

🔴Vulnerability Details

3
GHSA
GHSA-77xx-wx8p-7pfj: A flaw was found in htmldoc in v12022-03-04
OSV
CVE-2021-23180: A flaw was found in htmldoc in v12022-03-02
CVEList
CVE-2021-23180: A flaw was found in htmldoc in v12022-03-02

📋Vendor Advisories

2
Ubuntu
HTMLDOC vulnerability2021-12-16
Debian
CVE-2021-23180: htmldoc - A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in f...2021
CVE-2021-23180 — NULL Pointer Dereference | cvebase