9.8
CVSSv3

CVE-2021-23158

Published: 16/03/2022 Updated: 22/03/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an malicious user to execute arbitrary code and denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

htmldoc project htmldoc 1.9.12

Vendor Advisories

Debian Bug report logs - #989437 CVE-2021-23165 CVE-2021-26948 CVE-2021-26259 CVE-2021-26252 CVE-2021-23206 CVE-2021-23191 CVE-2021-23180 CVE-2021-23158 Package: htmldoc; Maintainer for htmldoc is Håvard Flaget Aasen <haavard_aasen@yahoono>; Source for htmldoc is src:htmldoc (PTS, buildd, popcon) Reported by: Moritz Muehle ...
A buffer overflow was discovered in HTMLDOC, a HTML processor that generates indexed HTML, PS, and PDF, which could potentially result in the execution of arbitrary code In addition a number of crashes were addressed For the stable distribution (buster), these problems have been fixed in version 193-1+deb10u2 We recommend that you upgrade your ...
A security issue was found in htmldoc before version 1912 Double-free in function pspdf_export() in ps-pdfcxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service ...