CVE-2021-20308 - log back

CVE-2021-20308 edited at 05 Apr 2021 20:57:49
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
Description
+ Integer overflow in htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.
References
+ https://bugzilla.redhat.com/show_bug.cgi?id=1946289
+ https://github.com/michaelrsweet/htmldoc/issues/423
+ https://github.com/michaelrsweet/htmldoc/commit/6a8322a718b2ba5c440bd33e6f26d9e281c39654
Notes
CVE-2021-20308 created at 05 Apr 2021 20:55:49