Bugzilla – Bug 1186805
VUL-0: CVE-2021-26252: htmldoc: heap-buffer-overflow in pspdf_prepare_page()
Last modified: 2021-06-07 14:54:23 UTC
A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service. Reference: https://github.com/michaelrsweet/htmldoc/issues/412 Upstream patch: https://github.com/michaelrsweet/htmldoc/commit/369b2ea1fd0d0537ba707f20a2f047b6afd2fbdc References: https://bugzilla.redhat.com/show_bug.cgi?id=1967009 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-26252
Affected packages: - SUSE:SLE-11:Update/htmldoc 1.8.27 - openSUSE:Factory/htmldoc 1.9.11 Upstream patch [0]. [0] https://github.com/michaelrsweet/htmldoc/commit/369b2ea1fd0d0537ba707f20a2f047b6afd2fbdc.patch
*** Bug 1186807 has been marked as a duplicate of this bug. ***
*** Bug 1186808 has been marked as a duplicate of this bug. ***
*** Bug 1186809 has been marked as a duplicate of this bug. ***
n/a for Factory/TW that already has 1.9.12 including the fix not on any product for Code12, not in Code15 only maintained in SMT 11 SP3, not planning to fix there. 369b2ea1fd0d0537ba707f20a2f047b6afd2fbdc is part of 1.9.12