Closed Crispy-fried-chicken closed 1 week ago
Looks like the same issue could happen here...
[master 6fb16b8] Update file_basename implementation to handle really long filenames (Issue #532)
@michaelrsweet is there any need to request a CVEID because of the high priority here?
I really don’t think so. We really didn’t need one for the other bug, and it isn’t like you could do anything besides crash the program.
But crashing the program itself is a consequence, so don’t we need to inform users by applying for CVEID?
Crash != CVE
Hi, we have detected that your project may be vulnerable to NULL Pointer Dereference in the function of
file_basename
in the file ofhtmldoc/file.c
. It shares similarities to a recent CVE disclosure CVE-2021-23180 in the htmldoc.The source vulnerability information is as follows:
Would you help to check if this bug is true? If it's true, I'd like to open a PR for that if necessary. Thank you for your effort and patience!