PT-2022-22432 · Md2Roff · Md2Roff

Published

2022-07-02

·

Updated

2025-04-09

·

CVE-2022-34913

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions md2roff version 1.7
Description The issue is a stack-based buffer overflow that occurs when processing a Markdown file containing a large number of consecutive characters. It's noted that the vendor's position is that the product is not intended for untrusted input.
Recommendations For md2roff version 1.7, consider avoiding the use of this version for processing untrusted Markdown files until a fix is available. As a temporary workaround, restrict the input to trusted sources to minimize the risk of exploitation.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-34913

Affected Products

Md2Roff