CVE-2021-43579 EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 7.3% (pctl 94)
Patch early
A public exploit exists.
Description
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 7.35% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2022-01-10 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| debian | debian linux |
| htmldoc project | htmldoc |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HTMLDOC 1.9.13 - Stack Buffer Overflow | 2025-09-16 |
References
- https://github.com/michaelrsweet/htmldoc/commit/27d08989a5a567155d506ac870ae7d8cc88fa58b
- https://github.com/michaelrsweet/htmldoc/compare/v1.9.12...v1.9.13
- https://github.com/michaelrsweet/htmldoc/issues/453
- https://github.com/michaelrsweet/htmldoc/issues/456
- https://lists.debian.org/debian-lts-announce/2022/02/msg00022.html
- https://github.com/michaelrsweet/htmldoc/commit/27d08989a5a567155d506ac870ae7d8cc88fa58b
- https://github.com/michaelrsweet/htmldoc/compare/v1.9.12...v1.9.13
- https://github.com/michaelrsweet/htmldoc/issues/453
- https://github.com/michaelrsweet/htmldoc/issues/456
- https://lists.debian.org/debian-lts-announce/2022/02/msg00022.html
→ the Explorer · watch your stack · NVD