CVE-2021-34121: High severity htmldoc vulnerability
Published Jul 18, 2023
·Updated
An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parsetree() in toc.cxx, this possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution.
Affected Software
2 affected componentsFixes available
debian/htmldoc<=1.9.11-4+deb11u3
1.9.16-11.9.20-1
Htmldoc Project Htmldoc=1.9.12
Remediation
Event History
Jul 18, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
02:15 PM
Description
Jan 8, 2025
Data Sourced
via Launchpad·04:22 AM
Description
Jan 12, 2025
Data Sourced
via Ubuntu·04:22 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2021-34121?
CVE-2021-34121 is an Out of Bounds flaw discovered in htmodoc 1.9.12 in the function parse_tree() in toc.cxx.
2
What is the impact of CVE-2021-34121?
The vulnerability may lead to memory layout information leaking and can be used in a chain of vulnerabilities to achieve code execution.
3
What software versions are affected by CVE-2021-34121?
CVE-2021-34121 affects Htmldoc 1.9.12.
4
How severe is CVE-2021-34121?
CVE-2021-34121 has a severity score of 7.8, which is considered high.
5
How can I fix CVE-2021-34121?
It is recommended to update to a patched version of Htmldoc to fix CVE-2021-34121.