Buffer overflow in Liblouis - CVE-2017-13740
Published: August 29, 2017 / Updated: August 8, 2020
Vulnerability identifier: #VU38402
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13740
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
There is a stack-based buffer overflow in Liblouis 3.2.0, triggered in the function parseChars() in compileTranslationTable.c, that will lead to denial of service or possibly unspecified other impact.
Affected software
Liblouis
Fedora
liblouis
Fedora
liblouis
How to mitigate CVE-2017-13740
Install update from vendor's website.
liblouis - addressed in versions 2.6.2-12.fc26, 2.6.2-12.fc27