CVE-2024-45508: Critical severity htmldoc vulnerability
Published Sep 1, 2024
·Updated
HTMLDOC before 1.9.19 has an out-of-bounds write in parseparagraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node.
Affected Software
2 affected componentsFixes available
debian/htmldoc<=1.9.11-4+deb11u3, <=1.9.16-1
1.9.20-1
Htmldoc Project Htmldoc<1.9.19
Remediation
Patch Available
Event History
Sep 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 27, 2025
Data Sourced
via Ubuntu·11:42 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-45508?
CVE-2024-45508 is classified as a medium severity vulnerability due to the risk of an out-of-bounds write.
2
How do I fix CVE-2024-45508?
To fix CVE-2024-45508, you should upgrade to HTMLDOC version 1.9.20-1 or later.
3
Which versions of HTMLDOC are affected by CVE-2024-45508?
HTMLDOC versions prior to 1.9.20 are affected by CVE-2024-45508.
4
What impact does CVE-2024-45508 have on the system?
CVE-2024-45508 can allow an attacker to exploit the out-of-bounds write, potentially leading to arbitrary code execution.
5
Is there a workaround for CVE-2024-45508 until I can update?
There are no known effective workarounds for CVE-2024-45508, so updating to a patched version is recommended.