Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-8184

Опубликовано: 02 авг. 2019
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
liblouisfixed2.6.2-1package
liblouisfixed2.5.3-3+deb8u1jessiepackage
liblouisnot-affectedwheezypackage

Примечания

  • https://github.com/liblouis/liblouis/issues/425

  • https://bugzilla.redhat.com/show_bug.cgi?id=1492701

  • Introduced by: https://github.com/liblouis/liblouis/commit/26ca8619a29951d6b4acf8b7a732a8b35e4e7bd3 (liblouis_2_5_0)

  • Fixed in merge: https://github.com/liblouis/liblouis/commit/dc97ef791a4fae9da11592c79f9f79e010596e0c#diff-7ade83431f79d2120c82012aee3b05c9L4524

  • CVE is for several buffer overflows in the findTable function, cf.

  • https://bugzilla.redhat.com/show_bug.cgi?id=1492701#c7

EPSS

Процентиль: 71%
0.00691
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 6 лет назад

A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.

CVSS3: 7.8
redhat
около 8 лет назад

A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.

CVSS3: 7.8
nvd
больше 6 лет назад

A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.

CVSS3: 8.8
github
больше 3 лет назад

A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.

suse-cvrf
почти 8 лет назад

Security update for liblouis

EPSS

Процентиль: 71%
0.00691
Низкий