PT-2014-8435 · Gnome+5 · Orca+5
Kirotawa
·
Published
2014-12-31
·
Updated
2023-03-03
·
CVE-2014-8184
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
liblouis versions 2.5.x before 2.5.4
Description
A stack-based buffer overflow was found in the
findTable() function in liblouis. This issue could allow an attacker to create a malicious file that causes applications using liblouis, such as Orca, to crash or potentially execute arbitrary code when the file is opened.Recommendations
For liblouis versions 2.5.x before 2.5.4, update to version 2.5.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
findTable() function in liblouis until a patch is available.Fix
Buffer Overflow
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Orca
Red Hat
Suse
Ubuntu
Liblouis