PT-2022-16532 · Htmldoc+5 · Htmldoc+5

Voiddy-Devo

·

Published

2022-04-04

·

Updated

2025-01-22

·

CVE-2022-24191

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HTMLDOC version 1.9.14
Description The issue is caused by an infinite loop in the gif read lzw function, which can lead to a pointer arbitrarily pointing to heap memory, resulting in a buffer overflow.
Recommendations For HTMLDOC version 1.9.14, consider disabling the gif read lzw function as a temporary workaround until a patch is available.

Exploit

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2627
ALT-PU-2022-2729
CVE-2022-24191
OPENSUSE-SU-2022_0113-1
ROSA-SA-2024-2399
USN-7225-1

Affected Products

Alt Linux
Astra Linux
Htmldoc
Linuxmint
Suse
Ubuntu