CVE-2021-26948: Null Pointer Dereference
Published Mar 3, 2022
·Updated
Last updated 8 January 2025
Other sources
Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file.
Affected Software
2 affected componentsFixes available
debian/htmldoc
1.9.11-4+deb11u31.9.16-11.9.20-1
Htmldoc Project Htmldoc=1.9.11
Remediation
Patch Available
Event History
Mar 3, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Jan 8, 2025
Data Sourced
via Launchpad·04:22 AM
Description
Jan 12, 2025
Data Sourced
via Ubuntu·04:22 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2021-26948?
CVE-2021-26948 is a vulnerability in htmldoc version 1.9.11 and earlier that may allow attackers to execute arbitrary code and cause a denial of service via a crafted HTML file.
2
What is the severity of CVE-2021-26948?
The severity of CVE-2021-26948 is high with a CVSS score of 7.8.
3
What software versions are affected by CVE-2021-26948?
Versions of htmldoc prior to 1.9.11 are affected by CVE-2021-26948.
4
How can the CVE-2021-26948 vulnerability be exploited?
Attackers can exploit the CVE-2021-26948 vulnerability by using a crafted HTML file to execute arbitrary code and cause a denial of service.
5
Is there a fix available for CVE-2021-26948?
Yes, updating htmldoc to version 1.9.11 or later will fix the CVE-2021-26948 vulnerability.