PT-2022-18802 · Htmldoc+3 · Htmldoc+3

Hdthkyo

·

Published

2022-03-24

·

Updated

2025-02-05

·

CVE-2022-28085

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions htmldoc version 31f7804
Description A flaw was found in htmldoc, where a heap buffer overflow in the function pdf write names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS).
Recommendations For htmldoc version 31f7804, as a temporary workaround, consider disabling the pdf write names function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-01900
CVE-2022-28085
OPENSUSE-SU-2024:12035-1
ROSA-SA-2024-2399
USN-7225-1

Affected Products

Astra Linux
Linuxmint
Ubuntu
Htmldoc