First published: Sun Sep 01 2024(Updated: )
HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/htmldoc | <=1.9.11-4+deb11u3<=1.9.16-1 | 1.9.20-1 |
Htmldoc | <1.9.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45508 is classified as a medium severity vulnerability due to the risk of an out-of-bounds write.
To fix CVE-2024-45508, you should upgrade to HTMLDOC version 1.9.20-1 or later.
HTMLDOC versions prior to 1.9.20 are affected by CVE-2024-45508.
CVE-2024-45508 can allow an attacker to exploit the out-of-bounds write, potentially leading to arbitrary code execution.
There are no known effective workarounds for CVE-2024-45508, so updating to a patched version is recommended.