[Bug 1230022] New: VUL-0: CVE-2024-45508: HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node.
https://bugzilla.suse.com/show_bug.cgi?id=1230022 Bug ID: 1230022 Summary: VUL-0: CVE-2024-45508: HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.6 Hardware: Other URL: https://smash.suse.de/issue/419446/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: pgajdos@suse.com Reporter: smash_bz@suse.de QA Contact: security-team@suse.de CC: abergmann@suse.com Target Milestone: --- Found By: Security Response Team Blocker: --- HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. Backport code-streams: openSUSE:Backports:SLE-12-SP1/htmldoc openSUSE:Backports:SLE-15-SP5:Update/htmldoc openSUSE:Backports:SLE-15-SP6:Update/htmldoc References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-45508 https://www.cve.org/CVERecord?id=CVE-2024-45508 https://github.com/michaelrsweet/htmldoc/blob/2d5b2ab9ddbf2aee2209010cebc11e... https://github.com/michaelrsweet/htmldoc/commit/2d5b2ab9ddbf2aee2209010cebc1... https://github.com/michaelrsweet/htmldoc/issues/528 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1230022 SMASH SMASH <smash_bz@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1230022 Marcus Meissner <meissner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Summary|VUL-0: CVE-2024-45508: |VUL-0: CVE-2024-45508: |HTMLDOC before 1.9.19 has |htmldoc: HTMLDOC before |an out-of-bounds write in |1.9.19 has an out-of-bounds |parse_paragraph in |write in parse_paragraph in |ps-pdf.cxx because of an |ps-pdf.cxx because of an |attempt to strip leading |attempt to strip leading |whitespace from a |whitespace from a |whitespace-only node. |whitespace-only node. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1230022 https://bugzilla.suse.com/show_bug.cgi?id=1230022#c1 --- Comment #1 from Petr Gajdos <pgajdos@suse.com> --- Submitted into devel project: https://build.opensuse.org/request/show/1198298 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1230022 https://bugzilla.suse.com/show_bug.cgi?id=1230022#c2 --- Comment #2 from Petr Gajdos <pgajdos@suse.com> --- Also submitted into: b15sp6, b15sp5, b12sp1 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1230022 https://bugzilla.suse.com/show_bug.cgi?id=1230022#c4 Petr Gajdos <pgajdos@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|pgajdos@suse.com |security-team@suse.de --- Comment #4 from Petr Gajdos <pgajdos@suse.com> --- Forwarded to Factory: https://build.opensuse.org/request/show/1198406 I believe all fixed. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1230022 https://bugzilla.suse.com/show_bug.cgi?id=1230022#c5 --- Comment #5 from Marcus Meissner <meissner@suse.com> --- openSUSE-SU-2024:0304-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1230022 CVE References: CVE-2024-45508 JIRA References: Sources used: openSUSE Backports SLE-15-SP5 (src): htmldoc-1.9.16-bp155.2.3.1 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1230022 https://bugzilla.suse.com/show_bug.cgi?id=1230022#c6 --- Comment #6 from Marcus Meissner <meissner@suse.com> --- openSUSE-SU-2024:0303-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1230022 CVE References: CVE-2024-45508 JIRA References: Sources used: openSUSE Backports SLE-15-SP6 (src): htmldoc-1.9.16-bp156.3.3.1 -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com