Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-17294

Опубликовано: 21 сент. 2018
Источник: debian

Описание

The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via out-of-bounds read) by crafting an input file with certain translation dictionaries.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
liblouisfixed3.7.0-1package
liblouisno-dsastretchpackage
liblouisignoredjessiepackage

Примечания

  • https://github.com/liblouis/liblouis/commit/5e4089659bb49b3095fa541fa6387b4c40d7396e

  • https://github.com/liblouis/liblouis/issues/635

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via out-of-bounds read) by crafting an input file with certain translation dictionaries.

CVSS3: 4.7
redhat
больше 7 лет назад

The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via out-of-bounds read) by crafting an input file with certain translation dictionaries.

CVSS3: 6.5
nvd
больше 7 лет назад

The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via out-of-bounds read) by crafting an input file with certain translation dictionaries.

suse-cvrf
больше 5 лет назад

Security update for liblouis

suse-cvrf
почти 7 лет назад

Security update for liblouis