Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for htmldoc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0046-1 Rating: important References: #1232380 Cross-References: CVE-2024-46478 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for htmldoc fixes the following issues: - CVE-2024-46478: Fixed buffer overflow when handling tabs through the parse_pre function (boo#1232380). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-46=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): htmldoc-1.9.16-bp157.3.3.1 References: https://www.suse.com/security/cve/CVE-2024-46478.html https://bugzilla.suse.com/1232380 . Update fixes important buffer overflow in htmldoc for openSUSE, potentially impacting system security and stability.. openSUSE security update, htmldoc patch, buffer overflow fix, important security advisory. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for htmldoc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0047-1 Rating: important References: #1232380 Cross-References: CVE-2024-46478 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for htmldoc fixes the following issues: - CVE-2024-46478: Fixed buffer overflow when handling tabs through the parse_pre function (boo#1232380). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2026-47=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64): htmldoc-1.9.16-bp156.3.6.1 References: https://www.suse.com/security/cve/CVE-2024-46478.html https://bugzilla.suse.com/1232380 . openSUSE htmldoc update fixes important buffer overflow issue; urgent patch recommended for vulnerabilities.. openSUSE htmldoc buffer overflow patch security update. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in htmldoc.. ========================================================================== Ubuntu Security Notice USN-7225-1 January 22, 2025 HTMLDOC vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in htmldoc. Software Description: - htmldoc: HTML processor that generates indexed HTML, PS, and PDF Details: It was discovered that HTMLDOC incorrectly handled memory in the image_set_mask, git_read_lzw, write_header and write_node functions, which could lead to a heap buffer overflow. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-0137, CVE-2022-24191, CVE-2022-34033, CVE-2022-34035) It was discovered that HTMLDOC incorrectly handled memory in the gif_get_code function, which could lead to a segmentation fault. If a user or application were tricked into opening a crafted GIF file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-0534) It was discovered that HTMLDOC did not perform proper bounds checks on image dimensions when loading JPEG images, which could lead to a buffer overflow. If a user or application were tricked into opening a crafted JPEG image, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-27114) It was discovered that HTMLDOC incorrectly handled memory in the pdf_write_names function, whichcould lead to a heap buffer overflow. If a user or application were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service or leak sensitive information. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-28085) It was discovered that HTMLDOC could be made to write out of bounds when attempting to strip whitespace. An attacker could use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-45508) It was discovered that HTMLDOC incorrectly handled memory in the parse_pre function, which could lead to a heap buffer overflow. If a user or application were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-46478) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 htmldoc 1.9.18-1ubuntu0.1 Ubuntu 24.04 LTS htmldoc 1.9.17-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS htmldoc 1.9.15-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS htmldoc 1.9.7-1ubuntu0.3+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS htmldoc 1.9.2-1ubuntu0.2+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS htmldoc 1.8.27-8ubuntu1.1+esm3 Available with Ubuntu Pro Ubuntu 14.04 LTS htmldoc 1.8.27-8ubuntu1+esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7225-1 CVE-2022-0137, CVE-2022-0534, CVE-2022-24191, CVE-2022-27114, CVE-2022-28085, CVE-2022-34033, CVE-2022-34035, CVE-2024-45508, CVE-2024-46478 Package Information: https://launchpad.net/ubuntu/+source/htmldoc/1.9.18-1ubuntu0.1 . Multiple vulnerabilities in HTMLDOC necessitate prompt patches to avert service disruptions and safeguard against memory exploitation risks.. html processor, heap overflow, buffer overflow, stack smashing. . Severity: Critical. LinuxSecurity.com Team
HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. (CVE-2024-45508) HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. (CVE-2024-46478) . MGASA-2024-0353 - Updated htmldoc packages fix security vulnerabilities Publication date: 09 Nov 2024 URL: https://advisories.mageia.org/MGASA-2024-0353.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-45508, CVE-2024-46478 HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. (CVE-2024-45508) HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. (CVE-2024-46478) References: - https://bugs.mageia.org/show_bug.cgi?id=33737 - - https://www.cve.org/CVERecord?id=CVE-2024-45508 - https://www.cve.org/CVERecord?id=CVE-2024-46478 SRPMS: - 9/core/htmldoc-1.9.15-3.1.mga9 . The latest htmldoc updates tackle significant vulnerabilities in Mageia, impacting various versions and releases.. htmldoc security, buffer overflow, Mageia advisory, software security issues, out-of-bounds write. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for htmldoc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0349-1 Rating: important References: #1232380 Cross-References: CVE-2024-46478 Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for htmldoc fixes the following issues: - CVE-2024-46478: Fixed a buffer overflow when handling tabs through the parse_pre function (boo#1232380). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-349=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): htmldoc-1.9.16-bp155.2.6.1 References: https://www.suse.com/security/cve/CVE-2024-46478.html https://bugzilla.suse.com/1232380 . This crucial software patch addresses a memory leak in imgtool, improving security for Debian systems.. openSUSE Security Update, htmldoc patch, buffer overflow fix. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for htmldoc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0303-1 Rating: moderate References: #1230022 Cross-References: CVE-2024-45508 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for htmldoc fixes the following issues: - CVE-2024-45508: Fixed an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node [boo#1230022]. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2024-303=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64): htmldoc-1.9.16-bp156.3.3.1 References: https://www.suse.com/security/cve/CVE-2024-45508.html https://bugzilla.suse.com/1230022 . Enhance your openSUSE security by upgrading HTMDoc due to moderate vulnerabilities. Follow our step-by-step guide for a successful patching process. openSUSE Security, htmldoc Update, Out-Of-Bounds Error, Security Patch. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for htmldoc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0304-1 Rating: moderate References: #1230022 Cross-References: CVE-2024-45508 Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for htmldoc fixes the following issues: - CVE-2024-45508: Fixed an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node [boo#1230022]. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-304=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): htmldoc-1.9.16-bp155.2.3.1 References: https://www.suse.com/security/cve/CVE-2024-45508.html https://bugzilla.suse.com/1230022 . A patch for htmldoc addressing CVE-2024-45508 has been released on openSUSE, classified with moderate risk.. htmldoc Security Update, openSUSE Advisory, Moderate Security Fix. . LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in HTMLDOC, the worst of which can lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202405-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: HTMLDOC: Multiple Vulnerabilities Date: May 04, 2024 Bugs: #780489 ID: 202405-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in HTMLDOC, the worst of which can lead to arbitrary code execution. Background ========== HTMLDOC is a HTML indexer and HTML to PS and PDF converter. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ app-text/htmldoc < 1.9.16 > = 1.9.16 Description =========== Multiple vulnerabilities have been discovered in HTMLDOC. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All HTMLDOC users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/htmldoc-1.9.16" References ========== [ 1 ] CVE-2021-20308 https://nvd.nist.gov/vuln/detail/CVE-2021-20308 [ 2 ] CVE-2021-23158 https://nvd.nist.gov/vuln/detail/CVE-2021-23158 [ 3 ] CVE-2021-23165 https://nvd.nist.gov/vuln/detail/CVE-2021-23165 [ 4 ] CVE-2021-23180 https://nvd.nist.gov/vuln/detail/CVE-2021-23180 [ 5 ] CVE-2021-23191 https://nvd.nist.gov/vuln/detail/CVE-2021-23191 [ 6 ] CVE-2021-23206 https://nvd.nist.gov/vuln/detail/CVE-2021-23206 [ 7 ] CVE-2021-26252 https://nvd.nist.gov/vuln/detail/CVE-2021-26252 [ 8 ] CVE-2021-26259 https://nvd.nist.gov/vuln/detail/CVE-2021-26259 [ 9 ] CVE-2021-26948 https://nvd.nist.gov/vuln/detail/CVE-2021-26948 [ 10 ] CVE-2021-33235 https://nvd.nist.gov/vuln/detail/CVE-2021-33235 [ 11 ] CVE-2021-33236 https://nvd.nist.gov/vuln/detail/CVE-2021-33236 [ 12 ] CVE-2021-40985 https://nvd.nist.gov/vuln/detail/CVE-2021-40985 [ 13 ] CVE-2021-43579 https://nvd.nist.gov/vuln/detail/CVE-2021-43579 [ 14 ] CVE-2022-0137 https://nvd.nist.gov/vuln/detail/CVE-2022-0137 [ 15 ] CVE-2022-0534 https://nvd.nist.gov/vuln/detail/CVE-2022-0534 [ 16 ] CVE-2022-24191 https://nvd.nist.gov/vuln/detail/CVE-2022-24191 [ 17 ] CVE-2022-27114 https://nvd.nist.gov/vuln/detail/CVE-2022-27114 [ 18 ] CVE-2022-28085 https://nvd.nist.gov/vuln/detail/CVE-2022-28085 [ 19 ] CVE-2022-34033 https://nvd.nist.gov/vuln/detail/CVE-2022-34033 [ 20 ] CVE-2022-34035 https://nvd.nist.gov/vuln/detail/CVE-2022-34035 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202405-07 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.