In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn't aligned correctly. In versions before GLIBC version 2.29 and if aligned correctly, it allows arbitrary writes anywhere in the program's . MGASA-2025-0097 - Updated man2html man2html packages fix security vulnerability Publication date: 15 Mar 2025 URL: https://advisories.mageia.org/MGASA-2025-0097.html Type: security Affected Mageia releases: 9 CVE: CVE-2021-40647 In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn't aligned correctly. In versions before GLIBC version 2.29 and if aligned correctly, it allows arbitrary writes anywhere in the program's memory. References: - https://bugs.mageia.org/show_bug.cgi?id=34072 - https://lists.fedoraproject.org/archives/list/
Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-710d9bad0b 2025-03-15 00:23:42.169970+00:00 -------------------------------------------------------------------------------- Name : man2html Product : Fedora 42 Version : 1.6 Release : 39.g.fc42 URL : Summary : Convert man pages to HTML - CGI scripts Description : man2html is a man page to HTML converter. This package contains CGI scripts that allow you to view, browse, and search man pages using a web server. -------------------------------------------------------------------------------- Update Information: Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 26 2025 Sérgio Basto - 1.6-39.g - Add more patches from Debian 004-spelling.patch 011-man2html-doctype-status.patch 012-man2html-TH.patch 013-man2html-file-link.patch 030-man2html-man-hyphens.patch 032-man2html-man-remove-LO-tags.patch 034-UTF8-charset.patch 036-fix-tbl-font-parsing.patch 037-man2html-Nm-and-Bk-mdoc.patch 038-man2html-colon-escape-sequence.patch 042-man2html-CVE-2021-40647.patch 043-man2html-fix-asan-issues.patch man2html-ungzip.patch rename to 024-man2html-uncompress.patch * Tue Feb 25 2025 Sérgio Basto - 1.6-38.g - Add -std=gnu17 to CFLAGS to fix the build * Fri Jan 17 2025 Fedora Release Engineering - 1.6-37.g - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2126813 - CVE-2021-40647 man2html: sys-apps/man2html: multiple vulnerabilities[epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126813 [ 2 ] Bug #2126814 - CVE-2021-40647 man2html: sys-apps/man2html: multiple vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126814 [ 3 ] Bug #2340816 - man2html: FTBFS in Fedora rawhide/f42 https://bugzilla.redhat.com/show_bug.cgi?id=2340816 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-710d9bad0b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . Revisions made in Fedora 42 for man2html, tackling compilation challenges and implementing updates to enhance both security and usability.. man page converter, Fedora Project updates, software patching. . Severity: Critical. LinuxSecurity.com Team
Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a778f51bce 2025-03-07 03:41:49.695819+00:00 -------------------------------------------------------------------------------- Name : man2html Product : Fedora 40 Version : 1.6 Release : 39.g.fc40 URL : Summary : Convert man pages to HTML - CGI scripts Description : man2html is a man page to HTML converter. This package contains CGI scripts that allow you to view, browse, and search man pages using a web server. -------------------------------------------------------------------------------- Update Information: Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 26 2025 Sérgio Basto - 1.6-39.g - Add more patches from Debian 004-spelling.patch 011-man2html-doctype-status.patch 012-man2html-TH.patch 013-man2html-file-link.patch 030-man2html-man-hyphens.patch 032-man2html-man-remove-LO-tags.patch 034-UTF8-charset.patch 036-fix-tbl-font-parsing.patch 037-man2html-Nm-and-Bk-mdoc.patch 038-man2html-colon-escape-sequence.patch 042-man2html-CVE-2021-40647.patch 043-man2html-fix-asan-issues.patch man2html-ungzip.patch rename to 024-man2html-uncompress.patch * Tue Feb 25 2025 Sérgio Basto - 1.6-38.g - Add -std=gnu17 to CFLAGS to fix the build * Fri Jan 17 2025 Fedora Release Engineering - 1.6-37.g - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Thu Jul 18 2024 Fedora Release Engineering - 1.6-36.g - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2126814 - CVE-2021-40647 man2html: sys-apps/man2html: multiple vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126814 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a778f51bce' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . Ubuntu 22.04 update addresses CUPS privacy issues with code enhancements and system optimizations for better usability. Fedora 40 man2html update, security patches, build adjustments. . Severity: Important. LinuxSecurity.com Team
Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-538f2e492d 2025-03-07 02:22:25.692724+00:00 -------------------------------------------------------------------------------- Name : man2html Product : Fedora 41 Version : 1.6 Release : 39.g.fc41 URL : Summary : Convert man pages to HTML - CGI scripts Description : man2html is a man page to HTML converter. This package contains CGI scripts that allow you to view, browse, and search man pages using a web server. -------------------------------------------------------------------------------- Update Information: Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 26 2025 Sérgio Basto - 1.6-39.g - Add more patches from Debian 004-spelling.patch 011-man2html-doctype-status.patch 012-man2html-TH.patch 013-man2html-file-link.patch 030-man2html-man-hyphens.patch 032-man2html-man-remove-LO-tags.patch 034-UTF8-charset.patch 036-fix-tbl-font-parsing.patch 037-man2html-Nm-and-Bk-mdoc.patch 038-man2html-colon-escape-sequence.patch 042-man2html-CVE-2021-40647.patch 043-man2html-fix-asan-issues.patch man2html-ungzip.patch rename to 024-man2html-uncompress.patch * Tue Feb 25 2025 Sérgio Basto - 1.6-38.g - Add -std=gnu17 to CFLAGS to fix the build * Fri Jan 17 2025 Fedora Release Engineering - 1.6-37.g - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2126814 - CVE-2021-40647 man2html: sys-apps/man2html: multiple vulnerabilities[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2126814 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-538f2e492d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . The latest man2html update for Fedora 41 introduces several patches and enhancements aimed at resolving security vulnerabilities. Discover all the details today.. Fedora updates, man2html security, patch management, build fixes for Linux, software updates. . LinuxSecurity.com Team
It has been reported that one can tweak man2html remotely into consuming all available memory. This has been fixed by Nicolás Lichtmaier with help of Stephan Kulow.. ---------------------------------------------------------------------------- Debian Security Advisory DSA-035-1
Get the latest Linux and open source security news straight to your inbox.