Описание
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.
A flaw was found in Tesseract, an open-source Optical Character Recognition (OCR) engine. A remote attacker could exploit this by providing a specially crafted .traineddata LSTM model component. When Tesseract's deserializer processes this component during OCR recognition, an unchecked integer multiplication can occur, leading to an undersized buffer and a heap out-of-bounds write. This vulnerability could result in a denial of service or potentially arbitrary code execution.
Меры по смягчению последствий
To mitigate this issue, avoid processing .traineddata files from untrusted sources with Tesseract. Ensure that only .traineddata files from known, reputable origins are used for OCR recognition.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | tesseract | Affected | ||
| Red Hat Enterprise Linux 8 | tesseract | Affected | ||
| Red Hat Enterprise Linux 9 | tesseract | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .tra ...
EPSS
7.1 High
CVSS3