Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-24191

Опубликовано: 04 апр. 2022
Источник: debian
EPSS Низкий

Описание

In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
htmldocfixed1.9.15-1package
htmldocfixed1.9.11-4+deb11u3bullseyepackage
htmldocfixed1.9.3-1+deb10u4busterpackage

Примечания

  • https://github.com/michaelrsweet/htmldoc/commit/fb0334a51300988e9b83b9870d4063e86002b077 (v1.9.15)

  • https://github.com/michaelrsweet/htmldoc/issues/470

  • Hang in CLI tool, no security impact

EPSS

Процентиль: 10%
0.00036
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 4 года назад

In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.

CVSS3: 5.5
nvd
почти 4 года назад

In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.

CVSS3: 5.5
github
почти 4 года назад

In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.

EPSS

Процентиль: 10%
0.00036
Низкий