CVE-2019-17544

CRITICAL

GNU Aspell < 0.60.8 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.

References (8)

Core 8
Core References
Third Party Advisory x_refsource_misc
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16109
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4155-1/
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/10/msg00027.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4155-2/
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2021/07/msg00021.html
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4948

Scores

CVSS v3 9.1
EPSS 0.0036
EPSS Percentile 58.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-125
Status published
Products (6)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 19.04
gnu/aspell < 0.60.8
Published Oct 14, 2019
Tracked Since Feb 18, 2026