There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will cause a buffer overflow/Address boundary error in the jpeg_read_scanlines function.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade htmldoc | May 16, 2022 | May 9, 2022 |
| Gentoo Linux | — | Upgrade app-text/htmldoc. | May 6, 2024 | May 9, 2022 |
| Suse | — | Upgrade htmldoc | Oct 26, 2022 | May 9, 2022 |
| Ubuntu | — | Upgrade htmldoc (Ubuntu Pro)Upgrade htmldoc | Jan 24, 2025 | May 9, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub