Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.853863
Category:SuSE Local Security Checks
Title:openSUSE: Security Advisory for htmldoc (openSUSE-SU-2021:0882-1)
Summary:The remote host is missing an update for the 'htmldoc'; package(s) announced via the openSUSE-SU-2021:0882-1 advisory.
Description:Summary:
The remote host is missing an update for the 'htmldoc'
package(s) announced via the openSUSE-SU-2021:0882-1 advisory.

Vulnerability Insight:
This update for htmldoc fixes the following issues:

htmldoc was updated to version 1.9.12:

* Fixed buffer-overflow CVE-2021-20308 ( boo#1184424 )

* Fixed a crash bug with 'data:' URIs and EPUB output

* Fixed several other crash bugs

* Fixed JPEG error handling

* Fixed some minor issues

* Removed the bundled libjpeg, libpng, and zlib.

update to 1.9.11:

- Added high-resolution desktop icons for Linux.

- Updated the internal HTTP library to fix truncation of redirection URLs

- Fixed a regression in the handling of character entities for UTF-8 input

- The `--numbered` option did not work when the table-of-contents was
disabled

- Updated local zlib to v1.2.11.

- Updated local libpng to v1.6.37.

- Fixed packaging issues on macOS and Windows

- Now ignore sRGB profile errors in PNG files

- The GUI would crash when saving

- Page comments are now allowed in `pre` text

update to 1.9.9:

- Added support for a `HTMLDOC.filename` META keyword that controls the
filename reported in CGI mode the default remains 'htmldoc.pdf' (Issue
#367)

- Fixed a paragraph formatting issue with large inline images (Issue #369)

- Fixed a buffer underflow issue (Issue #370)

- Fixed PDF page numbers (Issue #371)

- Added support for a new `L` header/footer format (`$LETTERHEAD`), which
inserts a letterhead image at its full size (Issue #372, Issue #373,
Issue #375)

- Updated the build documentation (Issue #374)

- Refactored the PRE rendering code to work around compiler optimization
bugs

- Added support for links with targets (Issue #351)

- Fixed a table rowspan + valign bug (Issue #360)

- Added support for data URIs (Issue #340)

- HTMLDOC no longer includes a PDF table of contents when converting a
single web page (Issue #344)

- Updated the markdown support with external links, additional inline
markup, and hard line breaks.

- Links in markdown text no longer render with a leading space as part of
the link (Issue #346)

- Fixed a buffer underflow bug discovered by AddressSanitizer.

- Fixed a bug in UTF-8 support (Issue #348)

- PDF output now includes the base language of the input document(s)

- Optimized the loading of font widths (Issue #354)

- Optimized PDF page resources (Issue #356)

- Optimized the base memory used for font widths (Issue #357)

- Added proper `& shy ` support (Issue #361)

- Title files can now be markdown.

- The GUI did not sup ...

Description truncated. Please see the references for more information.

Affected Software/OS:
'htmldoc' package(s) on openSUSE Leap 15.2.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-20308
[debian-lts-announce] 20210701 [SECURITY] [DLA 2700-1] htmldoc security update
https://lists.debian.org/debian-lts-announce/2021/07/msg00000.html
https://bugzilla.redhat.com/show_bug.cgi?id=1946289
https://github.com/michaelrsweet/htmldoc/issues/423
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.