Bugzilla – Bug 1186815
VUL-0: CVE-2021-23180: htmldoc: null pointer dereference in function in file_extension()
Last modified: 2021-06-07 14:50:24 UTC
A flaw was found in htmldoc in v1.9.12. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service. Reference: https://github.com/michaelrsweet/htmldoc/issues/418 Upstream patch: https://github.com/michaelrsweet/htmldoc/commit/19c582fb32eac74b57e155cffbb529377a9e751a References: https://bugzilla.redhat.com/show_bug.cgi?id=1967041 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-23180
Affected packages: - SUSE:SLE-11:Update/htmldoc 1.8.27 - openSUSE:Factory/htmldoc 1.9.11 Upstream patch [0]. [0] https://github.com/michaelrsweet/htmldoc/commit/19c582fb32eac74b57e155cffbb529377a9e751a.patch
n/a for Factory/TW that already has 1.9.12 including the fix not on any product for Code12, not in Code15 only maintained in SMT 11 SP3, not planning to fix there.
19c582fb32eac74b57e155cffbb529377a9e751a is part of 1.9.12