First published: Mon May 09 2022(Updated: )
There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will cause a buffer overflow/Address boundary error in the jpeg_read_scanlines function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Htmldoc Project Htmldoc | =1.9.16 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27114 is a vulnerability in htmldoc 1.9.16 that can cause an integer overflow and result in a buffer overflow.
The severity of CVE-2022-27114 is medium with a CVSS score of 5.5.
CVE-2022-27114 affects Htmldoc version 1.9.16.
CVE-2022-27114 affects Debian Debian Linux version 9.0.
To fix CVE-2022-27114, update htmldoc to a version that includes the fix for the vulnerability.