Mageia 2024-0353: htmldoc Security Advisory Updates
Summary
HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in
ps-pdf.cxx because of an attempt to strip leading whitespace from a
whitespace-only node. (CVE-2024-45508)
HTMLDOC v1.9.18 contains a buffer overflow in parse_pre
function,ps-pdf.cxx:5681. (CVE-2024-46478)
References
- https://bugs.mageia.org/show_bug.cgi?id=33737
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/RNU4P4P7ZCF5TYOAPMGGBX2KSE6IHZFT/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45508
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-46478
Resolution
MGASA-2024-0353 - Updated htmldoc packages fix security vulnerabilities
SRPMS
- 9/core/htmldoc-1.9.15-3.1.mga9