Lucene search

K
ubuntuUbuntuUSN-5438-1
HistoryMay 23, 2022 - 12:00 a.m.

HTMLDOC vulnerability

2022-05-2300:00:00
ubuntu.com
51
ubuntu 20.04 lts
ubuntu 18.04 esm
htmldoc
memory management
denial of service
arbitrary code
security vulnerability

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.006

Percentile

79.6%

Releases

  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM

Packages

  • htmldoc - HTML processor that generates indexed HTML, PS, and PDF

Details

It was discovered that HTMLDOC did not properly manage memory under certain
circumstances. If a user were tricked into opening a specially crafted HTML
file, a remote attacker could possibly use this issue to cause HTMLDOC to
crash, resulting in a denial of service, or possibly execute arbitrary code.

OSVersionArchitecturePackageVersionFilename
Ubuntu20.04noarchhtmldoc< 1.9.7-1ubuntu0.3UNKNOWN
Ubuntu20.04noarchhtmldoc-common< 1.9.7-1ubuntu0.3UNKNOWN
Ubuntu18.04noarchhtmldoc< 1.9.2-1ubuntu0.2UNKNOWN
Ubuntu18.04noarchhtmldoc-common< 1.9.2-1ubuntu0.2UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.006

Percentile

79.6%