CVE-2022-28085

Name
CVE-2022-28085
Description
A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS).
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/michaelrsweet/htmldoc/issues/480
MISC https://github.com/michaelrsweet/htmldoc/commit/46c8ec2b9bccb8ccabff52d998c5eee77a228348

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:htmldoc_project:htmldoc:*:*:*:*:*:*:*:* htmldoc >= None < 2022-03-24
cpe:2.3:a:htmldoc_project:htmldoc:*:*:*:*:*:*:*:* htmldoc >= None < 1.9.16

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
htmldoc edge-community 1.9.21-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
htmldoc edge-community 1.9.20-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
htmldoc 3.22-community 1.9.20-r0 Celeste <cielesti@protonmail.com> possibly vulnerable