ELA-1474-1 catdoc security update

multiple vulnerabilities

2025-06-30
Packagecatdoc
Version1:0.94.3~git20160113.dbc9ec6+dfsg-1+deb9u2 (stretch), 1:0.95-4.1+deb11u1~deb10u1 (buster)
Related CVEs CVE-2024-48877 CVE-2024-52035 CVE-2024-54028


Multiple vulnerabilities have been fixed in catdoc, a text extractor for MS-Office files.

CVE-2024-48877

memory corruption

CVE-2024-52035

integer overflow

CVE-2024-54028

integer underflow


For Debian 10 buster, these problems have been fixed in version 1:0.95-4.1+deb11u1~deb10u1.

For Debian 9 stretch, these problems have been fixed in version 1:0.94.3~git20160113.dbc9ec6+dfsg-1+deb9u2.

We recommend that you upgrade your catdoc packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.