CVE-2021-40647
Summary
| CVE | CVE-2021-40647 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-09 18:15:00 UTC |
| Updated | 2023-08-08 14:22:00 UTC |
| Description | In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn't aligned correctly. In version before GLIBC version 2.29 and aligned correctly, it allows arbitrary write anywhere in the programs memory. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Man2html Project | Man2html | 1.6g | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2021-40647 and CVE-2021-40648 · GitHub | MISC | gist.github.com | |
| man2html.com | MISC | man2html.com | |
| Commercial Distributor & Supply Company | North American | MISC | na.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.