#VU21946 Out-of-bounds read in Aspell - CVE-2019-17544
Published: October 20, 2019
Aspell
GNU
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when processing an isolated character within the acommon::unescape() function in common/getdata.cpp file in GNU Aspell. A remote attacker can create a specially crafted Excel file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system or crash the application.