CVE-2022-4741

MEDIUM

docconv <1.2.0 - Memory Corruption

Title source: llm
STIX 2.1

Description

A vulnerability was found in docconv up to 1.2.0 and classified as problematic. This issue affects the function ConvertDocx/ConvertODT/ConvertPages/ConvertXML/XMLToText. The manipulation leads to uncontrolled memory allocation. The attack may be initiated remotely. Upgrading to version 1.2.1 is able to address this issue. The name of the patch is 42bcff666855ab978e67a9041d0cdea552f20301. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216779.

Scores

CVSS v3 4.3
EPSS 0.0044
EPSS Percentile 63.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Details

CWE
CWE-789
Status published
Products (3)
code.sajari.com/docconv 0 - 1.2.1Go
sajari/docconv 0 - 1.2.1Go
search/docconv < 1.2.1
Published Dec 25, 2022
Tracked Since Feb 18, 2026