PT-2023-2375 · Liblouis+7 · Liblouis+7
Marsman1996
·
Published
2023-02-04
·
Updated
2025-01-20
·
CVE-2023-26768
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Liblouis version 3.24.0
Description
The issue is related to a buffer overflow that can be triggered by a remote attacker, potentially causing a denial of service. This is associated with the
compileTranslationTable.c and the lou setDataPath functions. The vulnerability involves uncontrolled copying of data, which can lead to service disruption.Recommendations
For Liblouis version 3.24.0, consider disabling the
lou setDataPath function and restricting access to the compileTranslationTable.c component until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Resource Exhaustion
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Debian
Liblouis
Linuxmint
Red Hat
Red Os
Suse
Ubuntu