File _patchinfo of Package patchinfo.17395
<patchinfo incident="17395">
<category>security</category>
<rating>important</rating>
<packager>pgajdos</packager>
<issue id="1192357" tracker="bnc"/>
<issue id="1194487" tracker="bnc"/>
<issue id="1195758" tracker="bnc"/>
<issue id="2021-40985" tracker="cve" />
<issue id="2021-43579" tracker="cve" />
<issue id="2022-0534" tracker="cve" />
<summary>Security update for htmldoc</summary>
<description>
htmldoc was updated to fix issues:
- CVE-2021-40985: Fixed buffer overflow may lead to DoS via a crafted BMP image (bsc#1192357)
- CVE-2021-43579: Fixed stack-based buffer overflow in image_load_bmp() results in remote code execution if the victim converts an HTML document linking to a crafted BMP file (bsc#1194487)
- CVE-2022-0534: Fixed stack out-of-bounds read in gif_get_code() when opening a malicious GIF file results in a segmentation fault (bsc#1195758)
</description>
</patchinfo>