CVE-2021-43579: Buffer Overflow
Published Nov 12, 2021
·Updated
A stack-based buffer overflow in imageloadbmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.
Affected Software
2 affected components
Htmldoc Project Htmldoc<=1.9.13
Debian Debian Linux=9.0
Remediation
Patch Available
Patch Available
Event History
Nov 12, 2021
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
Description
Sep 16, 2025
Exploit Published
12:00 AM
Oct 31, 2025
Known Exploited
06:46 AM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-43579.
2
What is the severity of CVE-2021-43579?
The severity of CVE-2021-43579 is high (7.8).
3
How does CVE-2021-43579 occur?
CVE-2021-43579 occurs due to a stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13.
4
What is the potential impact of CVE-2021-43579?
The potential impact of CVE-2021-43579 is remote code execution if the victim converts an HTML document linking to a crafted BMP file.
5
How can I fix CVE-2021-43579?
To fix CVE-2021-43579, upgrade to a version of HTMLDOC greater than 1.9.13.