SUSE-SU-2022:14898-1
Dashboard / Vulnerabilities / SUSE-SU-2022:14898-1
SUSE-SU-2022:14898-1
Summary: Security update for htmldoc
Details: This update for htmldoc fixes the following issues: - CVE-2019-19630: Fixed stack-based buffer overflow in the hd_strlcpy() function in string.c via a crafted HTML document (bsc#1158802). - CVE-2021-20308: Fixed integer overflow in image_load_gif() (bsc#1184424). - CVE-2022-0534: Fixed stack out-of-bounds read in gif_get_code() when opening a malicious GIF file results in a segmentation fault (bsc#1195758).
References: https://www.suse.com/support/update/announcement/2022/suse-su-202214898-1/, https://bugzilla.suse.com/1158802, https://bugzilla.suse.com/1184424, https://bugzilla.suse.com/1195758, https://www.suse.com/security/cve/CVE-2019-19630, https://www.suse.com/security/cve/CVE-2021-20308, https://www.suse.com/security/cve/CVE-2022-0534
Affected packages
Package
Name: htmldoc
Purl: pkg:rpm/suse/htmldoc&distro=Subscription%20Management%20Tool%2011%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
