Out-of-bounds read in opencc - CVE-2018-16982

 

Out-of-bounds read in opencc - CVE-2018-16982

Published: February 3, 2026


Vulnerability identifier: #VU122272
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16982
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the BinaryDict::NewFromFile() function in BinaryDict.cpp. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory on the system.


Affected software

opencc
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Desktop Applications Module
openSUSE Leap
opencc-debuginfo
opencc-devel
libopencc2
opencc
opencc-data
libopencc2-debuginfo
opencc-debugsource

How to mitigate CVE-2018-16982

Install updates from vendor's website.

opencc - update to 1.0.6
opencc-debuginfo - addressed in versions 1.0.3-5.3.1, 1.0.5-150000.5.3.1
opencc-devel - addressed in versions 1.0.3-5.3.1, 1.0.5-150000.5.3.1
libopencc2 - addressed in versions 1.0.3-5.3.1, 1.0.5-150000.5.3.1
opencc - addressed in versions 1.0.3-5.3.1, 1.0.5-150000.5.3.1
opencc-data - addressed in versions 1.0.3-5.3.1, 1.0.5-150000.5.3.1
libopencc2-debuginfo - update to 1.0.5-150000.5.3.1
opencc-debugsource - update to 1.0.5-150000.5.3.1

External References

Related Security Bulletins