Heap-based buffer overflow in Aspell - CVE-2019-25051
Published: August 3, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list). A remote attacker can trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Anolis OS
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for ARM 64
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
aspell (Debian package)
libpspell15-debuginfo
libpspell15
aspell-devel
libaspell15-debuginfo-32bit
libaspell15-debuginfo
libaspell15-32bit
libaspell15
aspell-ispell
aspell-debugsource
aspell-debuginfo
aspell
aspell (Red Hat package)
aspell-help
aspell-32bit
aspell-debuginfo-32bit
aspell (Ubuntu package)
libaspell15 (Ubuntu package)
app-text/aspell
How to mitigate CVE-2019-25051
libpspell15-debuginfo - addressed in versions 0.60.6.1-18.11.1, 0.60.8-3.3.1
libpspell15 - addressed in versions 0.60.6.1-18.11.1, 0.60.8-3.3.1
aspell-devel - addressed in versions 0.60.6.1-18.11.1, 0.60.8-3.3.1
libaspell15-debuginfo-32bit - update to 0.60.6.1-18.11.1
libaspell15-debuginfo - addressed in versions 0.60.6.1-18.11.1, 0.60.8-3.3.1
libaspell15-32bit - update to 0.60.6.1-18.11.1
libaspell15 - addressed in versions 0.60.6.1-18.11.1, 0.60.8-3.3.1
aspell-ispell - addressed in versions 0.60.6.1-18.11.1, 0.60.6-26.36.1
aspell-debugsource - addressed in versions 0.60.6.1-18.11.1, 0.60.6-26.36.1, 0.60.8-3.3.1
aspell-debuginfo - addressed in versions 0.60.6.1-18.11.1, 0.60.6-26.36.1, 0.60.8-3.3.1
aspell - addressed in versions 0.60.6.1-18.11.1, 0.60.6-26.36.1, 0.60.8-3.3.1
aspell - update to 0.60.6.1-22
aspell (Red Hat package) - update to 0.60.6.1-22.el8
aspell-debuginfo - addressed in versions 0.60.6.1-28, 0.60.6.1-30
aspell - addressed in versions 0.60.6.1-28, 0.60.6.1-30
aspell-help - addressed in versions 0.60.6.1-28, 0.60.6.1-30
aspell-devel - addressed in versions 0.60.6.1-28, 0.60.6.1-30
aspell-debugsource - addressed in versions 0.60.6.1-28, 0.60.6.1-30
aspell-32bit - update to 0.60.6-26.36.1
aspell-debuginfo-32bit - update to 0.60.6-26.36.1
aspell (Ubuntu package) - addressed in versions 0.60.7~20110707-4ubuntu0.2, 0.60.8-1ubuntu0.1, 0.60.8-2ubuntu0.1
libaspell15 (Ubuntu package) - addressed in versions 0.60.7~20110707-4ubuntu0.2, 0.60.8-1ubuntu0.1, 0.60.8-2ubuntu0.1
app-text/aspell - update to 0.60.8-r3
aspell - update to 0.60.8-7.fc34
External References
- https://github.com/gnuaspell/aspell/commit/0718b375425aad8e54e1150313b862e4c6fd324a
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=18462
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/aspell/OSV-2020-521.yaml
- https://lists.debian.org/debian-lts-announce/2021/07/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H7E4EI7F6TVN7K6XWU6HSANMCOKKEREE/
Related Security Bulletins
- Remote code execution in GNU Aspell
- Debian update for aspell
- Red Hat Enterprise Linux 8 update for aspell
- SUSE update for aspell
- SUSE update for aspell
- SUSE update for aspell
- Ubuntu update for aspell
- Gentoo update for GNU Aspell
- openEuler update for aspell
- openEuler 22.03 LTS SP3 update for aspell
- openEuler 22.03 LTS SP1 update for aspell
- Fedora 34 update for aspell
- Anolis OS update for aspell