CVE-2022-0137: Buffer Overflow
Published Nov 14, 2022
·Updated
A heap buffer overflow in imagesetmask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffer boundaries.
Affected Software
2 affected componentsFixes available
debian/htmldoc<=1.9.11-4+deb11u3
1.9.16-11.9.20-1
Htmldoc Project Htmldoc<1.9.15
Remediation
Patch Available
Event History
Nov 14, 2022
CVE Published
via MITRE·05:01 PM
Data Sourced
via MITRE·05:01 PM
DescriptionSeverityWeakness
Jan 23, 2025
Data Sourced
via Launchpad·11:42 PM
Description
Feb 1, 2025
Data Sourced
via Ubuntu·11:01 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-0137?
CVE-2022-0137 is a heap buffer overflow vulnerability in the image_set_mask function of HTMLDOC before version 1.9.15.
2
How severe is CVE-2022-0137?
CVE-2022-0137 has a severity score of 5.5 (high).
3
How does CVE-2022-0137 affect HTMLDOC?
CVE-2022-0137 affects HTMLDOC versions up to and excluding 1.9.15.
4
How can an attacker exploit CVE-2022-0137?
An attacker can exploit CVE-2022-0137 by triggering a heap buffer overflow in the image_set_mask function of HTMLDOC, allowing them to write outside the buffer boundaries.
5
Are there any fixes for CVE-2022-0137?
Yes, the vulnerability has been fixed in version 1.9.15 of HTMLDOC.