A stack-based buffer overflow in imageloadbmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.
{
"unresolved_ranges": [
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"vendor_product": "debian:debian_linux",
"extracted_events": [
{
"introduced": "9.0"
},
{
"last_affected": "9.0"
}
]
}
]
}{
"cpe": "cpe:2.3:a:htmldoc_project:htmldoc:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.13"
}
]
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"75444419729333380443052050884245593707",
"52953918717421753729251150082072149909",
"152886919627866368274563169380254036118",
"198152111810803722130400047947566870774",
"304108754680799189403228624423602673270",
"157781778164509291172586315901535516558",
"70669642789662802104105858184899219014",
"168806463103019594349885454995563723793"
]
},
"signature_version": "v1",
"source": "https://github.com/michaelrsweet/htmldoc/commit/27d08989a5a567155d506ac870ae7d8cc88fa58b",
"signature_type": "Line",
"target": {
"file": "htmldoc/image.cxx"
},
"id": "CVE-2021-43579-3dcf72e3",
"deprecated": false
},
{
"digest": {
"length": 4321.0,
"function_hash": "79376633260742945387846236869644820982"
},
"signature_version": "v1",
"source": "https://github.com/michaelrsweet/htmldoc/commit/27d08989a5a567155d506ac870ae7d8cc88fa58b",
"signature_type": "Function",
"target": {
"function": "image_load_bmp",
"file": "htmldoc/image.cxx"
},
"id": "CVE-2021-43579-8b2b6b1d",
"deprecated": false
}
]
"2026-07-09T00:37:46Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43579.json"