Your submission was sent successfully! Close

USN-5438-1: HTMLDOC vulnerability

23 May 2022

HTMLDOC could be made to crash or run programs if it received specially crafted HTML files.

Releases

Packages

  • htmldoc - HTML processor that generates indexed HTML, PS, and PDF

Details

It was discovered that HTMLDOC did not properly manage memory under certain
circumstances. If a user were tricked into opening a specially crafted HTML
file, a remote attacker could possibly use this issue to cause HTMLDOC to
crash, resulting in a denial of service, or possibly execute arbitrary code.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 20.04
Ubuntu 18.04

In general, a standard system update will make all the necessary changes.

References