CVE-2019-19630 describes a stack-based buffer overflow vulnerability in HTMLDOC 1.9.7, specifically within the hd_strlcpy() function when processing crafted HTML documents. This flaw impacts various distributions of HTMLDOC, including those found in Debian and Fedora. Rated with a CVSS score of 7.8 (High), this vulnerability requires user interaction (UI:R) and local access (AV:L) to exploit, but can lead to high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). The attack complexity is low (AC:L), making it relatively easy to execute if an attacker gains local access and can entice a user to open a malicious file. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting it is not widely known or actively targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.9.7CPE matchmatch criteria | cpe:2.3:a:htmldoc_project:htmldoc:1.9.7:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.