cbcvebase.

Debian Htmldoc vulnerabilities

24 known vulnerabilities affecting debian/htmldoc.

Total CVEs
24
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3MEDIUM1LOW20

Vulnerabilities

Page 2 of 2
CVE-2022-27114P4MEDIUMCVSS 5.5fixed in htmldoc 1.9.15-2 (bookworm)2022
CVE-2022-27114 [MEDIUM] CVE-2022-27114: htmldoc - There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cx... There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will cause a buffer overflow/Address boundary error in the jpeg_read_scanlines function. Scope:
debian
CVE-2022-0534P4LOWCVSS 5.5fixed in htmldoc 1.9.15-1 (bookworm)2022
CVE-2022-0534 [MEDIUM] CVE-2022-0534: htmldoc - A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bound... A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault). Scope: local bookworm: resolved (fixed in 1.9.15-1) bullseye: resolved (fixed in 1.9.11-4+deb11u2) forky: resolved (fixed in 1.9.15-1) sid: resolved (fixed
debian
CVE-2022-24191P4LOWCVSS 5.5fixed in htmldoc 1.9.15-1 (bookworm)2022
CVE-2022-24191 [MEDIUM] CVE-2022-24191: htmldoc - In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a p... In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow. Scope: local bookworm: resolved (fixed in 1.9.15-1) bullseye: resolved (fixed in 1.9.11-4+deb11u3) forky: resolved (fixed in 1.9.15-1) sid: resolved (fixed in 1.9.15-1) trixie: resolved (fixed in 1.9.15-1)
debian
CVE-2021-40985P4LOWCVSS 5.5fixed in htmldoc 1.9.13-1 (bookworm)2021
CVE-2021-40985 [MEDIUM] CVE-2021-40985: htmldoc - A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to ca... A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp. Scope: local bookworm: resolved (fixed in 1.9.13-1) bullseye: resolved (fixed in 1.9.11-4+deb11u1) forky: resolved (fixed in 1.9.13-1) sid: resolved (fixed in 1.9.13-1) trixie: resolved (fixed in 1.9.13-1)
debian
Debian Htmldoc vulnerabilities | cvebase