PT-2022-11288 · Glibc+3 · Glibc+3

Untaman

·

Published

2021-09-07

·

Updated

2025-09-04

·

CVE-2021-40647

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions man2html version 1.6g GLIBC versions prior to 2.29
Description A specific string read from a file can overwrite the size parameter in the top chunk of the heap, causing a segmentation abort if the heap size parameter is not aligned correctly. In versions before GLIBC 2.29, and when aligned correctly, this allows arbitrary write access anywhere in the program's memory.
Recommendations For man2html version 1.6g, consider updating to a version that uses GLIBC version 2.29 or later to mitigate the risk. For GLIBC versions prior to 2.29, as a temporary workaround, consider restricting access to files that could contain the specific string, until a patch is available.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-11258
CVE-2021-40647
MGASA-2025-0097

Affected Products

Debian
Glibc
Red Os
Man2Html