First published: Wed Jan 08 2025(Updated: )
It was discovered that HTMLDOC incorrectly handled certain inputs, which could lead to an integer overflow. An attacker could potentially use this issue to cause a denial of service or execute arbitrary code. (CVE-2021-20308) It was discovered that HTMLDOC incorrectly handled memory in pspdf_export, which could lead to a double-free. An attacker could potentially use this issue to cause a denial of service or execute arbitrary code. (CVE-2021-23158) It was discovered that HTMLDOC incorrectly handled memory when loading a JPEG image, which could lead to a NULL pointer dereference. An attacker could potentially use this issue to cause a denial of service. (CVE-2021-23191, CVE-2021-26948) It was discovered that HTMLDOC incorrectly handled certain inputs, which could lead to a stack buffer overflow. An attacker could potentially use this issue to cause a denial of service or execute arbitrary code. (CVE-2021-23206, CVE-2021-40985, CVE-2021-43579) It was discovered that HTMLDOC incorrectly handled memory in pdpdf_prepare_page and render_table_row, which could lead to a heap buffer overflow. An attacker could potentially use this issue to cause a denial of service or execute arbitrary code. (CVE-2021-26252, CVE-2021-26259) It was discovered that HTMLDOC incorrectly handled memory in parse_paragraph, which could lead to a heap buffer overflow. An attacker could potentially use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-34119) It was discovered that HTMLDOC incorrectly handled memory in parse_tree. An attacker could potentially use this issue to leak sensitive information. (CVE-2021-34121)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/htmldoc | <1.9.7-1ubuntu0.3+esm1 | 1.9.7-1ubuntu0.3+esm1 |
Ubuntu Linux | =20.04 | |
All of | ||
ubuntu/htmldoc | <1.9.2-1ubuntu0.2+esm1 | 1.9.2-1ubuntu0.2+esm1 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/htmldoc | <1.8.27-8ubuntu1.1+esm2 | 1.8.27-8ubuntu1.1+esm2 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/htmldoc | <1.8.27-8ubuntu1+esm3 | 1.8.27-8ubuntu1+esm3 |
Ubuntu Linux | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability USN-7189-1 has a high severity due to the potential for denial of service and arbitrary code execution.
To fix USN-7189-1, upgrade to the patched versions of htmldoc as specified in the advisory.
USN-7189-1 affects Ubuntu 20.04, 18.04, 16.04, and 14.04 with specified versions of htmldoc.
USN-7189-1 is an integer overflow vulnerability found in htmldoc.
Yes, USN-7189-1 could potentially allow an attacker to execute arbitrary code or cause a denial of service.