Buffer overflow in Liblouis - CVE-2017-13740

 

Buffer overflow in Liblouis - CVE-2017-13740

Published: August 29, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38402
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13740
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

There is a stack-based buffer overflow in Liblouis 3.2.0, triggered in the function parseChars() in compileTranslationTable.c, that will lead to denial of service or possibly unspecified other impact.


Affected software

Liblouis
Fedora
liblouis

How to mitigate CVE-2017-13740

Install update from vendor's website.

liblouis - addressed in versions 2.6.2-12.fc26, 2.6.2-12.fc27

External References

Related Security Bulletins