github.com/sajari/docconv
Activity
- Latest release
- 2y ago
- Total releases
- 13
- Cadence
- ~23 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Feb 06, 2014
| Version | Released | |
|---|---|---|
v1.3.8
patch
|
v1.3.8
patch
Dependencies (11)
+ 3 more |
|
v1.3.7
patch
|
v1.3.7
patch
Dependencies (10)
+ 2 more |
|
v1.3.6
patch
|
v1.3.6
patch
Dependencies (10)
+ 2 more |
|
v1.3.5
patch
|
v1.3.5
patch
Dependencies (10)
+ 2 more |
|
v1.3.4
patch
|
v1.3.4
patch
Dependencies (10)
+ 2 more |
|
v1.3.3
patch
|
v1.3.3
patch
Dependencies (10)
+ 2 more |
|
v1.3.2
patch
|
v1.3.2
patch
Dependencies (10)
+ 2 more |
|
v1.3.1
patch
|
v1.3.1
patch
Dependencies (10)
+ 2 more |
|
v1.3.0
minor
|
v1.3.0
minor
Dependencies (10)
+ 2 more |
|
v1.2.1
patch
|
v1.2.1
patch
Dependencies (8)
|
|
v1.2.0
minor
2 CVEs
CVE-2022-4741
GHSA-qvx2-59g8-8hph
GO-2022-1188
Dec 25, 2022
docconv vulnerable to Memory Allocation with Excessive Size Value
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
A vulnerability was found in docconv up to 1.2.0 and classified as problematic. This issue affects the function Fixed in
1.2.1
References Updated Mar 01, 2024 · Source: OSV.dev
CVE-2022-4643
GHSA-6m4h-hfpp-x8cx
GO-2022-1184
Dec 22, 2022
docconv OS Command Injection vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A vulnerability was found in docconv prior to version 1.2.1. It has been declared as critical. This vulnerability affects the function ConvertPDFImages of the file pdf_ocr.go. The manipulation of the argument path leads to os command injection. The attack can be initiated remotely. Upgrading to version 1.2.1 can address this issue. The name of the patch is b19021ade3d0b71c89d35cb00eb9e589a121faa5. It is recommended to upgrade the affected component. VDB-216502 is the identifier assigned to this vulnerability. Fixed in
1.2.1
References
Updated May 20, 2024 · Source: OSV.dev |
v1.2.0
minor
Dependencies (6)
|
|
v1.1.0
minor
2 CVEs
CVE-2022-4741
GHSA-qvx2-59g8-8hph
GO-2022-1188
Dec 25, 2022
docconv vulnerable to Memory Allocation with Excessive Size Value
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
A vulnerability was found in docconv up to 1.2.0 and classified as problematic. This issue affects the function Fixed in
1.2.1
References Updated Mar 01, 2024 · Source: OSV.dev
CVE-2022-4643
GHSA-6m4h-hfpp-x8cx
GO-2022-1184
Dec 22, 2022
docconv OS Command Injection vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A vulnerability was found in docconv prior to version 1.2.1. It has been declared as critical. This vulnerability affects the function ConvertPDFImages of the file pdf_ocr.go. The manipulation of the argument path leads to os command injection. The attack can be initiated remotely. Upgrading to version 1.2.1 can address this issue. The name of the patch is b19021ade3d0b71c89d35cb00eb9e589a121faa5. It is recommended to upgrade the affected component. VDB-216502 is the identifier assigned to this vulnerability. Fixed in
1.2.1
References
Updated May 20, 2024 · Source: OSV.dev |
v1.1.0
minor
|
|
v1.0.0
initial
2 CVEs
CVE-2022-4741
GHSA-qvx2-59g8-8hph
GO-2022-1188
Dec 25, 2022
docconv vulnerable to Memory Allocation with Excessive Size Value
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
A vulnerability was found in docconv up to 1.2.0 and classified as problematic. This issue affects the function Fixed in
1.2.1
References Updated Mar 01, 2024 · Source: OSV.dev
CVE-2022-4643
GHSA-6m4h-hfpp-x8cx
GO-2022-1184
Dec 22, 2022
docconv OS Command Injection vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A vulnerability was found in docconv prior to version 1.2.1. It has been declared as critical. This vulnerability affects the function ConvertPDFImages of the file pdf_ocr.go. The manipulation of the argument path leads to os command injection. The attack can be initiated remotely. Upgrading to version 1.2.1 can address this issue. The name of the patch is b19021ade3d0b71c89d35cb00eb9e589a121faa5. It is recommended to upgrade the affected component. VDB-216502 is the identifier assigned to this vulnerability. Fixed in
1.2.1
References
Updated May 20, 2024 · Source: OSV.dev |
v1.0.0
initial
|