CVE Vulnerabilities

CVE-2021-23158

Double Free

Published: Mar 16, 2022 | Modified: Mar 22, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Htmldoc Htmldoc_project 1.9.12 (including) 1.9.12 (including)
Htmldoc Ubuntu bionic *
Htmldoc Ubuntu esm-apps/bionic *
Htmldoc Ubuntu esm-apps/focal *
Htmldoc Ubuntu esm-apps/xenial *
Htmldoc Ubuntu esm-infra-legacy/trusty *
Htmldoc Ubuntu focal *
Htmldoc Ubuntu groovy *
Htmldoc Ubuntu hirsute *
Htmldoc Ubuntu impish *
Htmldoc Ubuntu kinetic *
Htmldoc Ubuntu lunar *
Htmldoc Ubuntu mantic *
Htmldoc Ubuntu trusty *
Htmldoc Ubuntu trusty/esm *
Htmldoc Ubuntu upstream *
Htmldoc Ubuntu xenial *

Potential Mitigations

References