HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document.
CPE | Name | Operator | Version |
---|---|---|---|
debian_linux | eq | 8.0 | |
debian_linux | eq | 9.0 | |
fedora | eq | 30 | |
fedora | eq | 31 | |
htmldoc | eq | 1.9.7 |
github.com/michaelrsweet/htmldoc/issues/370
lists.debian.org/debian-lts-announce/2019/12/msg00008.html
lists.debian.org/debian-lts-announce/2021/07/msg00000.html
lists.fedoraproject.org/archives/list/[email protected]/message/7MZLVUBON5AYWYTFTJ4HBSHGTQTY7KBN/
lists.fedoraproject.org/archives/list/[email protected]/message/FEUT3LG6DWTICKXYAN4SWOQWWCGHPLDJ/