Out-of-bounds write in Htmlcleaner - CVE-2023-34624
Published: August 28, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing untrusted input. A remote attacker can pass specially crafted object that uses cyclic dependencies to the application, trigger an out-of-bounds write and perform a denial of service (DoS) attack.
Affected software
Debian Linux
Ubuntu
Oracle Agile PLM Framework
libhtmlcleaner-java (Ubuntu package)
libhtmlcleaner-java (Debian package)
How to mitigate CVE-2023-34624
libhtmlcleaner-java (Ubuntu package) - addressed in versions Ubuntu Pro, 2.24-1+deb11u1build0.22.04.1
libhtmlcleaner-java (Debian package) - addressed in versions 2.24-1+deb11u1, 2.26-1+deb12u1