Out-of-bounds read in Aspell - CVE-2019-17544
Published: October 20, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when processing an isolated character within the acommon::unescape() function in common/getdata.cpp file in GNU Aspell. A remote attacker can create a specially crafted Excel file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system or crash the application.
Affected software
aspell (Debian package)
aspell (Alpine package)
aspell
aspell-debugsource
aspell-devel
aspell-help
aspell-debuginfo
openEuler
How to mitigate CVE-2019-17544
aspell (Debian package) - update to 0.60.7~20110707-6+deb10u1
aspell (Alpine package) - addressed in versions 0.60.6.1-r13, 0.60.6.1-r14
aspell - update to 0.60.6.1-27
aspell-debugsource - update to 0.60.6.1-27
aspell-devel - update to 0.60.6.1-27
aspell-help - update to 0.60.6.1-27
aspell-debuginfo - update to 0.60.6.1-27