Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2021-43579Out-of-bounds Write in Project Htmldoc

Severity
7.8HIGHNVD
OSV9.8
EPSS
5.6%
top 9.65%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 10
Latest updateSep 16

Description

A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debianhtmldoc_project/htmldoc< 1.9.11-4+deb11u1+3
Ubuntuhtmldoc_project/htmldoc< 1.8.27-8ubuntu1+esm3+3

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

4
OSV
HTMLDOC vulnerabilities2025-01-08
GHSA
GHSA-999x-mjp8-5gfp: A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 12022-01-11
OSV
CVE-2021-43579: A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 12022-01-10
CVEList
CVE-2021-43579: A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 12021-11-12

💥Exploits & PoCs

1
Exploit-DB
HTMLDOC 1.9.13 - Stack Buffer Overflow2025-09-16

📋Vendor Advisories

2
Ubuntu
HTMLDOC vulnerabilities2025-01-08
Debian
CVE-2021-43579: htmldoc - A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results i...2021
CVE-2021-43579 — Out-of-bounds Write in Project Htmldoc | cvebase