Buffer overflow in Liblouis - CVE-2017-13739

 

Buffer overflow in Liblouis - CVE-2017-13739

Published: August 29, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38401
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13739
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

There is a heap-based buffer overflow that causes a more than two thousand bytes out-of-bounds write in Liblouis 3.2.0, triggered in the function resolveSubtable() in compileTranslationTable.c. It will lead to denial of service or remote code execution.


Affected software

Liblouis
Fedora
liblouis

How to mitigate CVE-2017-13739

Install update from vendor's website.

liblouis - addressed in versions 2.6.2-12.fc26, 2.6.2-12.fc27

External References

Related Security Bulletins