CVE-2021-23180: Null Pointer Dereference
A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in fileextension(),in file.c may lead to execute arbitrary code and denial of service.
Other sources
A flaw was found in htmldoc in versions prior to 1.9.12. Null pointer dereference in fileextension(),in file.c may lead to execute arbitrary code and denial of service.
Reference: https://github.com/michaelrsweet/htmldoc/issues/418
Upstream patch: https://github.com/michaelrsweet/htmldoc/commit/19c582fb32eac74b57e155cffbb529377a9e751a
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-23180?
CVE-2021-23180 is a vulnerability found in htmldoc version 1.9.12 and earlier, which can lead to arbitrary code execution and denial of service.
How severe is CVE-2021-23180?
CVE-2021-23180 has a severity score of 7.8 (high).
What is the affected software of CVE-2021-23180?
The affected software of CVE-2021-23180 includes htmldoc version 1.9.12, as well as certain versions from different distributions such as Red Hat, Ubuntu, and Debian.
How can CVE-2021-23180 be exploited?
CVE-2021-23180 can be exploited through null pointer dereference in the file_extension() function in file.c.
Is there a fix for CVE-2021-23180?
Yes, fixes for CVE-2021-23180 are available. Please refer to the references provided for more information.