Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-20433

Опубликовано: 27 янв. 2020
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 6.4
CVSS3: 9.1

Описание

libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encoding is set to ucs-2 or ucs-4 outside of the application, as demonstrated by the ASPELL_CONF environment variable.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

eoan

not-affected

0.60.7-3ubuntu0.1
esm-infra-legacy/trusty

needed

esm-infra/bionic

needed

esm-infra/focal

not-affected

esm-infra/xenial

ignored

proposed fix would break other applications
focal

not-affected

groovy

not-affected

hirsute

not-affected

Показывать по

EPSS

Процентиль: 70%
0.00644
Низкий

6.4 Medium

CVSS2

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 5.8
redhat
больше 6 лет назад

libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encoding is set to ucs-2 or ucs-4 outside of the application, as demonstrated by the ASPELL_CONF environment variable.

CVSS3: 9.1
nvd
около 6 лет назад

libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encoding is set to ucs-2 or ucs-4 outside of the application, as demonstrated by the ASPELL_CONF environment variable.

CVSS3: 9.1
debian
около 6 лет назад

libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a s ...

suse-cvrf
больше 5 лет назад

Security update for aspell

github
больше 3 лет назад

libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encoding is set to ucs-2 or ucs-4 outside of the application, as demonstrated by the ASPELL_CONF environment variable.

EPSS

Процентиль: 70%
0.00644
Низкий

6.4 Medium

CVSS2

9.1 Critical

CVSS3