Описание
Security update for opencc
This update for opencc fixes the following issues:
Update to version 1.2.0.
Security issues fixed:
- CVE-2025-15536: specifically crafted string can lead to out-of-bounds read (bsc#1256930).
Other updates and bugfixes:
- Version 1.2.0:
- Fix the crash issue when reading configuration files.
- Add type definitions (Typing).
- Fix two out-of-bounds reading issues when handling truncated UTF-8 input.
Список пакетов
openSUSE Leap 16.0
libopencc1_2-1.2.0-160000.1.1
opencc-1.2.0-160000.1.1
opencc-data-1.2.0-160000.1.1
opencc-devel-1.2.0-160000.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1256930
- SUSE CVE CVE-2025-15536 page
Описание
A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. Patch name: 345c9a50ab07018f1b4439776bad78a0d40778ec. To fix this issue, it is recommended to deploy a patch.
Затронутые продукты
openSUSE Leap 16.0:libopencc1_2-1.2.0-160000.1.1
openSUSE Leap 16.0:opencc-1.2.0-160000.1.1
openSUSE Leap 16.0:opencc-data-1.2.0-160000.1.1
openSUSE Leap 16.0:opencc-devel-1.2.0-160000.1.1
Ссылки
- CVE-2025-15536
- SUSE Bug 1256930