Debian Htmldoc vulnerabilities
24 known vulnerabilities affecting debian/htmldoc.
Total CVEs
24
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3MEDIUM1LOW20
Vulnerabilities
Page 2 of 2
CVE-2022-27114P4MEDIUMCVSS 5.5fixed in htmldoc 1.9.15-2 (bookworm)2022
CVE-2022-27114 [MEDIUM] CVE-2022-27114: htmldoc - There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cx...
There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will cause a buffer overflow/Address boundary error in the jpeg_read_scanlines function.
Scope:
debian
CVE-2022-0534P4LOWCVSS 5.5fixed in htmldoc 1.9.15-1 (bookworm)2022
CVE-2022-0534 [MEDIUM] CVE-2022-0534: htmldoc - A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bound...
A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).
Scope: local
bookworm: resolved (fixed in 1.9.15-1)
bullseye: resolved (fixed in 1.9.11-4+deb11u2)
forky: resolved (fixed in 1.9.15-1)
sid: resolved (fixed
debian
CVE-2022-24191P4LOWCVSS 5.5fixed in htmldoc 1.9.15-1 (bookworm)2022
CVE-2022-24191 [MEDIUM] CVE-2022-24191: htmldoc - In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a p...
In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.9.15-1)
bullseye: resolved (fixed in 1.9.11-4+deb11u3)
forky: resolved (fixed in 1.9.15-1)
sid: resolved (fixed in 1.9.15-1)
trixie: resolved (fixed in 1.9.15-1)
debian
CVE-2021-40985P4LOWCVSS 5.5fixed in htmldoc 1.9.13-1 (bookworm)2021
CVE-2021-40985 [MEDIUM] CVE-2021-40985: htmldoc - A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to ca...
A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.
Scope: local
bookworm: resolved (fixed in 1.9.13-1)
bullseye: resolved (fixed in 1.9.11-4+deb11u1)
forky: resolved (fixed in 1.9.13-1)
sid: resolved (fixed in 1.9.13-1)
trixie: resolved (fixed in 1.9.13-1)
debian
← Previous2 / 2