Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73066

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.

A flaw was found in Tesseract, an open-source Optical Character Recognition (OCR) engine. A remote attacker could exploit this by providing a specially crafted .traineddata LSTM model component. When Tesseract's deserializer processes this component during OCR recognition, an unchecked integer multiplication can occur, leading to an undersized buffer and a heap out-of-bounds write. This vulnerability could result in a denial of service or potentially arbitrary code execution.

Меры по смягчению последствий

To mitigate this issue, avoid processing .traineddata files from untrusted sources with Tesseract. Ensure that only .traineddata files from known, reputable origins are used for OCR recognition.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tesseractAffected
Red Hat Enterprise Linux 8tesseractAffected
Red Hat Enterprise Linux 9tesseractAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2514011tesseract: Tesseract: Heap out-of-bounds write via crafted .traineddata

EPSS

Процентиль: 3%
0.00126
Низкий

7.1 High

CVSS3

Связанные уязвимости

ubuntu
18 дней назад

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.

nvd
18 дней назад

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.

debian
18 дней назад

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .tra ...

EPSS

Процентиль: 3%
0.00126
Низкий

7.1 High

CVSS3