File _patchinfo of Package patchinfo.17395

<patchinfo incident="17395">
  <category>security</category>
  <rating>important</rating>
  <packager>pgajdos</packager>
  <issue id="1192357" tracker="bnc"/>
  <issue id="1194487" tracker="bnc"/>
  <issue id="1195758" tracker="bnc"/>
  <issue id="2021-40985" tracker="cve" />
  <issue id="2021-43579" tracker="cve" />
  <issue id="2022-0534" tracker="cve" />

  <summary>Security update for htmldoc</summary>
  <description>
htmldoc was updated to fix issues:

- CVE-2021-40985: Fixed buffer overflow may lead to DoS via a crafted BMP image (bsc#1192357)
- CVE-2021-43579: Fixed stack-based buffer overflow in image_load_bmp() results in remote code execution if the victim converts an HTML document linking to a crafted BMP file (bsc#1194487)
- CVE-2022-0534: Fixed stack out-of-bounds read in gif_get_code() when opening a malicious GIF file results in a segmentation fault (bsc#1195758)
</description>
</patchinfo>
openSUSE Build Service is sponsored by