MGASA-2024-0353 - Updated htmldoc packages fix security vulnerabilities

Publication date: 09 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0353.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-45508,
     CVE-2024-46478

HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in
ps-pdf.cxx because of an attempt to strip leading whitespace from a
whitespace-only node. (CVE-2024-45508)
HTMLDOC v1.9.18 contains a buffer overflow in parse_pre
function,ps-pdf.cxx:5681. (CVE-2024-46478)

References:
- https://bugs.mageia.org/show_bug.cgi?id=33737
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/RNU4P4P7ZCF5TYOAPMGGBX2KSE6IHZFT/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45508
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-46478

SRPMS:
- 9/core/htmldoc-1.9.15-3.1.mga9

Mageia 2024-0353: htmldoc Security Advisory Updates

HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node

Summary

HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. (CVE-2024-45508) HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. (CVE-2024-46478)

References

- https://bugs.mageia.org/show_bug.cgi?id=33737

- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/RNU4P4P7ZCF5TYOAPMGGBX2KSE6IHZFT/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45508

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-46478

Resolution

MGASA-2024-0353 - Updated htmldoc packages fix security vulnerabilities

SRPMS

- 9/core/htmldoc-1.9.15-3.1.mga9

Severity
Publication date: 09 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0353.html
Type: security
CVE: CVE-2024-45508, CVE-2024-46478

Related News