{"id":"CVE-2022-0534","details":"A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).","modified":"2026-08-18T15:13:05.242455Z","published":"2022-02-09T22:03:41Z","related":["SUSE-SU-2022:14898-1"],"database_specific":{"cna_assigner":"fedora","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0534.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0534.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0534"},{"type":"REPORT","url":"https://github.com/michaelrsweet/htmldoc/issues/463"},{"type":"FIX","url":"https://github.com/michaelrsweet/htmldoc/commit/312f0f9c12f26fbe015cd0e6cefa40e4b99017d9"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2022/02/msg00022.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/michaelrsweet/htmldoc","events":[{"introduced":"b66755a38ac6b05275f4bb20ff2e854ef515dba9"},{"fixed":"312f0f9c12f26fbe015cd0e6cefa40e4b99017d9"}],"database_specific":{"cpe":"cpe:2.3:a:htmldoc_project:htmldoc:1.9.15:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.9.15"},{"last_affected":"1.9.15"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.9.15","htmldoc 1.9.15"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-0534.json","vanir_signatures_modified":"2026-08-18T15:13:05Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"61006888649969542788776187617613035012","length":1018},"id":"CVE-2022-0534-04cbff3a","signature_type":"Function","signature_version":"v1","source":"https://github.com/michaelrsweet/htmldoc/commit/312f0f9c12f26fbe015cd0e6cefa40e4b99017d9","target":{"file":"htmldoc/image.cxx","function":"gif_read_image"}},{"source":"https://github.com/michaelrsweet/htmldoc/commit/312f0f9c12f26fbe015cd0e6cefa40e4b99017d9","target":{"file":"htmldoc/image.cxx"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["217608819493624789691786009379105025882","39718001466982375851625521278008146146","220843239006393782119396818274077327800","135412956098730307979935368414269789938","279047646562669804342462782780734892588","40987235627613882659394359311630063746","323702403332425694384612584592530196892"]},"id":"CVE-2022-0534-50a64bb0","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0"}