- -------------------------------------------------------------------------
Debian LTS Advisory DLA-2928-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Thorsten Alteholz
February 26, 2022                             https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : htmldoc
Version        : 1.8.27-8+deb9u2
CVE ID         : CVE-2021-40985 CVE-2021-43579 CVE-2022-0534


Several issues have been found in htmldoc, an HTML processor that 
generates indexed HTML, PS, and PDF.

CVE-2022-0534

      A crafted GIF file could lead to a stack out-of-bounds read,
      which could result in a crash (segmentation fault).

CVE-2021-43579

      Converting an HTML document, which links to a crafted BMP file,
      could lead to a stack-based buffer overflow, which could result
      in remote code execution.

CVE-2021-40985

      A crafted BMP image could lead to a buffer overflow, which could
      cause a denial of service.


For Debian 9 stretch, these problems have been fixed in version
1.8.27-8+deb9u2.

We recommend that you upgrade your htmldoc packages.

For the detailed security status of htmldoc please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/htmldoc

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-2928-1: htmldoc security update

February 26, 2022
Several issues have been found in htmldoc, an HTML processor that generates indexed HTML, PS, and PDF

Summary

Several issues have been found in htmldoc, an HTML processor that
generates indexed HTML, PS, and PDF.

CVE-2022-0534

A crafted GIF file could lead to a stack out-of-bounds read,
which could result in a crash (segmentation fault).

CVE-2021-43579

Converting an HTML document, which links to a crafted BMP file,
could lead to a stack-based buffer overflow, which could result
in remote code execution.

CVE-2021-40985

A crafted BMP image could lead to a buffer overflow, which could
cause a denial of service.


For Debian 9 stretch, these problems have been fixed in version
1.8.27-8+deb9u2.

We recommend that you upgrade your htmldoc packages.

For the detailed security status of htmldoc please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/htmldoc

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
Package : htmldoc
Version : 1.8.27-8+deb9u2
CVE ID : CVE-2021-40985 CVE-2021-43579 CVE-2022-0534

Related News