{"id":"CVE-2022-27114","details":"There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img-\u003ewidth' and 'img-\u003eheight' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will cause a buffer overflow/Address boundary error in the jpeg_read_scanlines function.","modified":"2026-08-18T16:28:59.485918Z","published":"2022-05-09T16:52:39Z","related":["openSUSE-SU-2024:12071-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/27xxx/CVE-2022-27114.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/27xxx/CVE-2022-27114.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-27114"},{"type":"REPORT","url":"https://github.com/michaelrsweet/htmldoc/issues/471"},{"type":"FIX","url":"https://github.com/michaelrsweet/htmldoc/commit/31f780487e5ddc426888638786cdc47631687275"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2022/05/msg00014.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/michaelrsweet/htmldoc","events":[{"introduced":"8b15a4e4fc58f4dbbecb91c5ca256a5dde28b793"},{"fixed":"31f780487e5ddc426888638786cdc47631687275"}],"database_specific":{"cpe":"cpe:2.3:a:htmldoc_project:htmldoc:1.9.16:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.9.16"},{"last_affected":"1.9.16"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.9.16"],"database_specific":{"vanir_signatures":[{"id":"CVE-2022-27114-973186cc","signature_type":"Line","signature_version":"v1","source":"https://github.com/michaelrsweet/htmldoc/commit/31f780487e5ddc426888638786cdc47631687275","target":{"file":"htmldoc/image.cxx"},"deprecated":false,"digest":{"line_hashes":["22248037274654815650576322048949287649","296267264495823945779616527713243343029","54805180142347034579293677483579791376","20168580982717471945539945481714769220","161029606450311038018640252069572140345","44015766389042975539425594357402522582","199150106324938499033452393139848187681","319593469495359680306054830735473771766","199852375355020133944898896514129910403","216794987705941529715646134661982004094","297929791160051720547755394787491271325","7171333243352453904152759386472981638","51235282975610117606622240123798757686","139219188293486094321898282517797944219","95795465467944516194981923126261552544","187404233367137448172080560522809448340","260172315706847100484704933799299393600","74720969679059144997190065584026944843","268732769885590353792037465098898972395","281414488574503611417848351362295128022","138700746721977183646352493457492251959"],"threshold":0.9}},{"signature_version":"v1","source":"https://github.com/michaelrsweet/htmldoc/commit/31f780487e5ddc426888638786cdc47631687275","target":{"file":"htmldoc/image.cxx","function":"image_load_gif"},"deprecated":false,"digest":{"function_hash":"241568264683061213505846123332327175641","length":1959},"id":"CVE-2022-27114-9bd92723","signature_type":"Function"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/michaelrsweet/htmldoc/commit/31f780487e5ddc426888638786cdc47631687275","target":{"function":"image_load_jpeg","file":"htmldoc/image.cxx"},"deprecated":false,"digest":{"length":1690,"function_hash":"73575095114162104851611625724241060175"},"id":"CVE-2022-27114-dd877a75"},{"digest":{"length":4174,"function_hash":"92107085259171046339019667125662630305"},"id":"CVE-2022-27114-ef3bc290","signature_type":"Function","signature_version":"v1","source":"https://github.com/michaelrsweet/htmldoc/commit/31f780487e5ddc426888638786cdc47631687275","target":{"file":"htmldoc/image.cxx","function":"image_load_png"},"deprecated":false},{"source":"https://github.com/michaelrsweet/htmldoc/commit/31f780487e5ddc426888638786cdc47631687275","target":{"file":"htmldoc/image.cxx","function":"image_load_bmp"},"deprecated":false,"digest":{"function_hash":"206302635082091458458529011910038932243","length":4392},"id":"CVE-2022-27114-f8105265","signature_type":"Function","signature_version":"v1"}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-27114.json","vanir_signatures_modified":"2026-08-18T16:28:59Z"}}],"schema_version":"1.9.0"}