CVE-2022-28085: Buffer Overflow
Published Apr 27, 2022
·Updated
A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdfwritenames in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS).
Affected Software
3 affected componentsFixes available
debian/htmldoc
1.9.11-4+deb11u31.9.16-11.9.20-1
Htmldoc Project Htmldoc<2022-03-24
Htmldoc Project Htmldoc<1.9.16
Remediation
Event History
Apr 27, 2022
CVE Published
via MITRE·02:19 AM
Data Sourced
via MITRE·02:19 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 23, 2025
Data Sourced
via Launchpad·11:42 PM
Description
Feb 1, 2025
Data Sourced
via Ubuntu·11:01 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this flaw in htmldoc?
The vulnerability ID of this flaw in htmldoc is CVE-2022-28085.
2
What is the severity rating of CVE-2022-28085?
CVE-2022-28085 has a severity rating of 7.8 (high).
3
What is the affected software for CVE-2022-28085?
The affected software for CVE-2022-28085 is Htmldoc Project Htmldoc up to version 2022-03-24.
4
What is the description of the vulnerability in htmldoc?
A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS).
5
How can I fix CVE-2022-28085?
To fix CVE-2022-28085, it is recommended to update Htmldoc to a version after 2022-03-24.