PT-2014-8435 · Gnome+5 · Orca+5

Kirotawa

·

Published

2014-12-31

·

Updated

2023-03-03

·

CVE-2014-8184

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions liblouis versions 2.5.x before 2.5.4
Description A stack-based buffer overflow was found in the findTable() function in liblouis. This issue could allow an attacker to create a malicious file that causes applications using liblouis, such as Orca, to crash or potentially execute arbitrary code when the file is opened.
Recommendations For liblouis versions 2.5.x before 2.5.4, update to version 2.5.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the findTable() function in liblouis until a patch is available.

Fix

Buffer Overflow

Stack Overflow

Weakness Enumeration

Related Identifiers

CESA-2017_3111
CVE-2014-8184
RHSA-2017:3111
RHSA-2017_3111
SUSE-SU-2017:3078-1
SUSE-SU-2017_3078-1
USN-3474-1

Affected Products

Centos
Orca
Red Hat
Suse
Ubuntu
Liblouis