CVE-2021-43579
on github
Published
Severity
CVSS v3:
7.8 HIGH
CVSS v2:
6.8 MEDIUM
Description
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.
References
- https://github.com/michaelrsweet/htmldoc/issues/453
- https://github.com/michaelrsweet/htmldoc/compare/v1.9.12...v1.9.13
- https://github.com/michaelrsweet/htmldoc/commit/27d08989a5a567155d506ac870ae7d8cc88fa58b
- https://github.com/michaelrsweet/htmldoc/issues/456
- https://lists.debian.org/debian-lts-announce/2022/02/msg00022.html
Configurations
CPE23 | Version Start | Version End | Exact Version |
---|---|---|---|
cpe:2.3:a:htmldoc_project:htmldoc:*:*:*:*:*:*:*:* | n/a | 1.9.13 (including) | * |
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | n/a | n/a | 9.0 |