PT-2022-25737 · Md2Roff · Md2Roff

Published

2022-09-21

·

Updated

2025-04-09

·

CVE-2022-41220

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions md2roff version 1.9
Description The issue is a stack-based buffer overflow that can occur when processing a Markdown file. It's noted that the vendor considers the product not intended for untrusted input.
Recommendations For md2roff version 1.9, consider avoiding the use of this version with untrusted Markdown files until a fix is available. As a temporary workaround, restrict the input to trusted sources to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-41220

Affected Products

Md2Roff