From 7d9d089a012fd0128c929c9808b85e48104cfea9 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Mon, 26 Feb 2024 12:30:16 +0000 Subject: [ GLSA 202402-31 ] GNU Aspell: Heap Buffer Overflow Bug: https://bugs.gentoo.org/803113 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202402-31.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 glsa-202402-31.xml diff --git a/glsa-202402-31.xml b/glsa-202402-31.xml new file mode 100644 index 00000000..b428da9d --- /dev/null +++ b/glsa-202402-31.xml @@ -0,0 +1,42 @@ + + + + GNU Aspell: Heap Buffer Overflow + A vulnerability has been discovered in GNU Aspell which leads to a heap buffer overflow. + aspell + 2024-02-26 + 2024-02-26 + 803113 + remote + + + 0.60.8-r3 + 0.60.8-r3 + + + +

GNU Aspell is a popular spell-checker. Dictionaries are available for many languages.

+
+ +

Multiple vulnerabilities have been discovered in GNU Aspell. Please review the CVE identifiers referenced below for details.

+
+ +

GNU Aspell has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list)

+
+ +

There is no known workaround at this time.

+
+ +

All aspell users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-text/aspell-0.60.8-r3" + +
+ + CVE-2019-25051 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad