Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-0534

Опубликовано: 09 фев. 2022
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
htmldocfixed1.9.15-1package
htmldocfixed1.9.11-4+deb11u2bullseyepackage
htmldocfixed1.9.3-1+deb10u3busterpackage

Примечания

  • https://github.com/michaelrsweet/htmldoc/issues/463

  • Fixed by: https://github.com/michaelrsweet/htmldoc/commit/776cf0fc4c760f1fb7b966ce28dc92dd7d44ed50 (v1.9.15)

  • Fixed by: https://github.com/michaelrsweet/htmldoc/commit/312f0f9c12f26fbe015cd0e6cefa40e4b99017d9 (v1.9.15)

  • Crash in CLI tool, no security impact

EPSS

Процентиль: 35%
0.0014
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 4 года назад

A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).

CVSS3: 5.5
nvd
почти 4 года назад

A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).

CVSS3: 5.5
github
почти 4 года назад

A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).

EPSS

Процентиль: 35%
0.0014
Низкий