CVE-2021-43579
Gentoo Linux Security Advisory 202405-07
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.
Un desbordamiento de búfer en la región stack de la memoria en la función image_load_bmp() en HTMLDOC versiones anteriores a 1.9.13 incluyéndola, resulta en una ejecución de código remota si la víctima convierte un documento HTML que enlaza con un archivo BMP diseñado
An update that solves four vulnerabilities and has two fixes is now available. Htmldoc was updated to fix issues. Fixed buffer overflow may lead to DoS via a crafted BMP image. Fixed stack-based buffer overflow in image_load_bmp results in remote code execution if the victim converts an HTML document linking to a crafted BMP file. Fixed stack out-of-bounds read in gif_get_code when opening a malicious GIF file results in a segmentation fault.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-12 CVE Reserved
- 2021-11-12 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2025-06-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://github.com/michaelrsweet/htmldoc/compare/v1.9.12...v1.9.13 | Release Notes | |
https://lists.debian.org/debian-lts-announce/2022/02/msg00022.html | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://github.com/michaelrsweet/htmldoc/issues/453 | 2024-08-04 | |
https://github.com/michaelrsweet/htmldoc/issues/456 | 2024-08-04 |
URL | Date | SRC |
---|---|---|
https://github.com/michaelrsweet/htmldoc/commit/27d08989a5a567155d506ac870ae7d8cc88fa58b | 2022-04-01 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Htmldoc Project Search vendor "Htmldoc Project" | Htmldoc Search vendor "Htmldoc Project" for product "Htmldoc" | <= 1.9.13 Search vendor "Htmldoc Project" for product "Htmldoc" and version " <= 1.9.13" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|