First published: Thu Mar 03 2022(Updated: )
Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Htmldoc Project Htmldoc | =1.9.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26948 is a vulnerability in htmldoc version 1.9.11 and earlier that may allow attackers to execute arbitrary code and cause a denial of service via a crafted HTML file.
The severity of CVE-2021-26948 is high with a CVSS score of 7.8.
Versions of htmldoc prior to 1.9.11 are affected by CVE-2021-26948.
Attackers can exploit the CVE-2021-26948 vulnerability by using a crafted HTML file to execute arbitrary code and cause a denial of service.
Yes, updating htmldoc to version 1.9.11 or later will fix the CVE-2021-26948 vulnerability.