CVE-2021-34121Out-of-bounds Read in Project Htmldoc

CWE-125Out-of-bounds Read7 documents6 sources
Severity
7.8HIGHNVD
OSV9.8
EPSS
0.0%
top 91.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 18
Latest updateJan 8

Description

An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debianhtmldoc_project/htmldoc< 1.9.13-1+2
Ubuntuhtmldoc_project/htmldoc< 1.8.27-8ubuntu1+esm3+3

Patches

🔴Vulnerability Details

4
OSV
HTMLDOC vulnerabilities2025-01-08
OSV
CVE-2021-34121: An Out of Bounds flaw was discovered in htmodoc 12023-07-18
GHSA
GHSA-vvmp-35v7-f6q6: An Out of Bounds flaw was discovered in htmodoc 12023-07-18
CVEList
CVE-2021-34121: An Out of Bounds flaw was discovered in htmodoc 12023-07-18

📋Vendor Advisories

2
Ubuntu
HTMLDOC vulnerabilities2025-01-08
Debian
CVE-2021-34121: htmldoc - An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() ...2021
CVE-2021-34121 — Out-of-bounds Read in Project Htmldoc | cvebase