Heap-based buffer overflow in Aspell - CVE-2019-25051

 

Heap-based buffer overflow in Aspell - CVE-2019-25051

Published: August 3, 2021


Vulnerability identifier: #VU55502
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-25051
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list). A remote attacker can trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Aspell
Gentoo Linux
Anolis OS
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for ARM 64
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
aspell (Debian package)
libpspell15-debuginfo
libpspell15
aspell-devel
libaspell15-debuginfo-32bit
libaspell15-debuginfo
libaspell15-32bit
libaspell15
aspell-ispell
aspell-debugsource
aspell-debuginfo
aspell
aspell (Red Hat package)
aspell-help
aspell-32bit
aspell-debuginfo-32bit
aspell (Ubuntu package)
libaspell15 (Ubuntu package)
app-text/aspell

How to mitigate CVE-2019-25051

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

aspell (Debian package) - update to 0.60.7~20110707-6+deb10u1
libpspell15-debuginfo - addressed in versions 0.60.6.1-18.11.1, 0.60.8-3.3.1
libpspell15 - addressed in versions 0.60.6.1-18.11.1, 0.60.8-3.3.1
aspell-devel - addressed in versions 0.60.6.1-18.11.1, 0.60.8-3.3.1
libaspell15-debuginfo-32bit - update to 0.60.6.1-18.11.1
libaspell15-debuginfo - addressed in versions 0.60.6.1-18.11.1, 0.60.8-3.3.1
libaspell15-32bit - update to 0.60.6.1-18.11.1
libaspell15 - addressed in versions 0.60.6.1-18.11.1, 0.60.8-3.3.1
aspell-ispell - addressed in versions 0.60.6.1-18.11.1, 0.60.6-26.36.1
aspell-debugsource - addressed in versions 0.60.6.1-18.11.1, 0.60.6-26.36.1, 0.60.8-3.3.1
aspell-debuginfo - addressed in versions 0.60.6.1-18.11.1, 0.60.6-26.36.1, 0.60.8-3.3.1
aspell - addressed in versions 0.60.6.1-18.11.1, 0.60.6-26.36.1, 0.60.8-3.3.1
aspell - update to 0.60.6.1-22
aspell (Red Hat package) - update to 0.60.6.1-22.el8
aspell-debuginfo - addressed in versions 0.60.6.1-28, 0.60.6.1-30
aspell - addressed in versions 0.60.6.1-28, 0.60.6.1-30
aspell-help - addressed in versions 0.60.6.1-28, 0.60.6.1-30
aspell-devel - addressed in versions 0.60.6.1-28, 0.60.6.1-30
aspell-debugsource - addressed in versions 0.60.6.1-28, 0.60.6.1-30
aspell-32bit - update to 0.60.6-26.36.1
aspell-debuginfo-32bit - update to 0.60.6-26.36.1
aspell (Ubuntu package) - addressed in versions 0.60.7~20110707-4ubuntu0.2, 0.60.8-1ubuntu0.1, 0.60.8-2ubuntu0.1
libaspell15 (Ubuntu package) - addressed in versions 0.60.7~20110707-4ubuntu0.2, 0.60.8-1ubuntu0.1, 0.60.8-2ubuntu0.1
app-text/aspell - update to 0.60.8-r3
aspell - update to 0.60.8-7.fc34

External References

Related Security Bulletins