PT-2014-8435 · Gnome+5 · Orca+5

Kirotawa

·

Publicado

2014-12-31

·

Atualizado

2023-03-03

·

CVE-2014-8184

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions liblouis versions 2.5.x before 2.5.4
Description A stack-based buffer overflow was found in the findTable() function in liblouis. This issue could allow an attacker to create a malicious file that causes applications using liblouis, such as Orca, to crash or potentially execute arbitrary code when the file is opened.
Recommendations For liblouis versions 2.5.x before 2.5.4, update to version 2.5.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the findTable() function in liblouis until a patch is available.

Correção

Buffer Overflow

Stack Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2017_3111
CVE-2014-8184
RHSA-2017:3111
RHSA-2017_3111
SUSE-SU-2017:3078-1
SUSE-SU-2017_3078-1
USN-3474-1

Produtos afetados

Centos
Orca
Red Hat
Suse
Ubuntu
Liblouis