CVE-2021-40647

MEDIUMCVSS 5.5/10EPSS 0.31%

Last modified

CVE-2021-40647 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn't aligned correctly. EPSS estimates a 0.31% chance of exploitation in the next 30 days.

Description

In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn't aligned correctly. In version before GLIBC version 2.29 and aligned correctly, it allows arbitrary write anywhere in the programs memory.

Metrics

CVSS 3.1
5.5/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Probability
0.31%

23.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Man2html ProjectMan2html1.6g

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-40647?
In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn't aligned correctly. In version before GLIBC version 2.29 and aligned correctly, it allows arbitrary write anywhere in the programs memory.
How severe is CVE-2021-40647?
CVE-2021-40647 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 0.31% probability of exploitation in the next 30 days.
How do I fix CVE-2021-40647?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-40647?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST