A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service. Reference: https://github.com/michaelrsweet/htmldoc/issues/413 Upstream patch: https://github.com/michaelrsweet/htmldoc/commit/369b2ea1fd0d0537ba707f20a2f047b6afd2fbdc
Created htmldoc tracking bugs for this issue: Affects: epel-7 [bug 1967017] Affects: fedora-all [bug 1967016]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
This has the same fix of 1967009 (CVE-2021-26252)
Please discard my previous message. This is a different bug than 1967009 (CVE-2021-26252). Upstream patch [0]. [0] https://github.com/michaelrsweet/htmldoc/commit/6e8a95561988500b5b5ae4861b3b0cbf4fba517f.patch
Why did it take so long for CVE-2021-23165 (this bug) and CVE-2021-23158 (bug 1967018) to be released? The bugs were opened in 2021-06 but CVEs were released in 2022-03, 9 months later. This is a big gap for those who depend on on CVEs to know what needs to be patched.