Vulnerability Description
xhtml_translate_entity in xhtml.c in epub2txt (aka epub2txt2) through 2.02 allows a stack-based buffer overflow via a crafted EPUB document.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Epub2Txt Project | Epub2Txt | <= 2.02 |
Related Weaknesses (CWE)
References
- https://cwe.mitre.org/data/definitions/121.htmlThird Party Advisory
- https://github.com/kevinboone/epub2txt2/issues/17ExploitIssue TrackingThird Party Advisory
- https://cwe.mitre.org/data/definitions/121.htmlThird Party Advisory
- https://github.com/kevinboone/epub2txt2/issues/17ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2022-23850?
CVE-2022-23850 is a vulnerability with a CVSS score of 7.8 (HIGH). xhtml_translate_entity in xhtml.c in epub2txt (aka epub2txt2) through 2.02 allows a stack-based buffer overflow via a crafted EPUB document.
How severe is CVE-2022-23850?
CVE-2022-23850 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23850?
Check the references section above for vendor advisories and patch information. Affected products include: Epub2Txt Project Epub2Txt.