CVE-2021-23165: Buffer Overflow
A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdfprepareoutpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
Other sources
A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdfprepareoutpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
Reference: https://github.com/michaelrsweet/htmldoc/issues/413
Upstream patch: https://github.com/michaelrsweet/htmldoc/commit/369b2ea1fd0d0537ba707f20a2f047b6afd2fbdc
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-23165.
What is the severity of CVE-2021-23165?
The severity of CVE-2021-23165 is critical with a severity value of 9.8.
What is the affected software?
The affected software is htmldoc before v1.9.12.
What is the description of CVE-2021-23165?
CVE-2021-23165 is a heap buffer overflow vulnerability in pspdf_prepare_outpages() in ps-pdf.cxx that may lead to executing arbitrary code and denial of service.
How can I fix CVE-2021-23165?
To fix CVE-2021-23165, it is recommended to update htmldoc to version 1.9.12 or newer.