High severity7.8NVD Advisory· Published Jan 10, 2022· Updated Jun 17, 2026
CVE-2021-43579
CVE-2021-43579
Description
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- Range: <=1.9.13
- HTMLDOC/HTMLDOCdescription
- osv-coords2 versionspkg:rpm/suse/htmldoc&distro=Subscription%20Management%20Tool%2011%20SP3pkg:rpm/opensuse/htmldoc&distro=openSUSE%20Tumbleweed
< 1.8.27-170.4.6.1+ 1 more
- (no CPE)range: < 1.8.27-170.4.6.1
- (no CPE)range: < 1.9.14-1.1
Patches
Vulnerability mechanics
References
5- github.com/michaelrsweet/htmldoc/commit/27d08989a5a567155d506ac870ae7d8cc88fa58bnvdPatchThird Party Advisory
- github.com/michaelrsweet/htmldoc/issues/453nvdExploitIssue TrackingPatchThird Party Advisory
- github.com/michaelrsweet/htmldoc/issues/456nvdExploitIssue TrackingPatchThird Party Advisory
- github.com/michaelrsweet/htmldoc/compare/v1.9.12...v1.9.13nvdRelease NotesThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/02/msg00022.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.