CVE-2022-4741

MEDIUM

docconv < 1.2.1 - Uncontrolled Memory Allocation in ConvertDocx/ConvertODT/ConvertPages/ConvertXML/XMLToText

Title source: llm
STIX 2.1

Description

A vulnerability was found in docconv up to 1.2.0 and classified as problematic. This issue affects the function ConvertDocx/ConvertODT/ConvertPages/ConvertXML/XMLToText. The manipulation leads to uncontrolled memory allocation. The attack may be initiated remotely. Upgrading to version 1.2.1 is able to address this issue. The name of the patch is 42bcff666855ab978e67a9041d0cdea552f20301. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216779.

References (5)

Core 5
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.216779
Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.216779
Patch, Third Party Advisory issue-tracking
https://github.com/sajari/docconv/pull/111
Release Notes, Third Party Advisory patch
https://github.com/sajari/docconv/releases/tag/v1.2.1

Scores

CVSS v3 4.3
EPSS 0.0076
EPSS Percentile 50.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Details

CWE
CWE-789
Status published
Products (3)
code.sajari.com/docconv 0 - 1.2.1Go
sajari/docconv 0 - 1.2.1Go
search/docconv < 1.2.1
Published Dec 25, 2022
Tracked Since Feb 18, 2026