CVE-2021-23158: Double Free
Published Jun 2, 2021
·Updated
A flaw was found in htmldoc in v1.9.12. Double-free in function pspdfexport(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service.
Affected Software
1 affected component
Htmldoc Project Htmldoc=1.9.12
Remediation
Event History
Jun 2, 2021
Data Sourced
via Red Hat·10:53 AM
DescriptionSeverityAffected Software
Mar 16, 2022
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-23158?
CVE-2021-23158 is a vulnerability found in htmldoc v1.9.12 that allows an attacker to execute arbitrary code and cause denial of service.
2
How severe is CVE-2021-23158?
CVE-2021-23158 has a severity rating of 9.8 (Critical).
3
How does CVE-2021-23158 occur?
CVE-2021-23158 occurs due to a double-free vulnerability in the pspdf_export() function in ps-pdf.cxx, which leads to a write-what-where condition.
4
What is the affected software by CVE-2021-23158?
The affected software by CVE-2021-23158 is htmldoc v1.9.12.
5
How can I fix CVE-2021-23158?
To fix CVE-2021-23158, update htmldoc to a version that contains the fix or apply the patch provided by the vendor.