Buffer overflow in Liblouis - CVE-2023-26768

 

Buffer overflow in Liblouis - CVE-2023-26768

Published: April 6, 2023


Vulnerability identifier: #VU74500
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-26768
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the lou_setDataPath in compileTranslationTable.c. A local user can trigger memory corruption and perform a denial of service (DoS) attack.

Affected software

Liblouis
Gentoo Linux
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Oracle Solaris
Desktop Applications Module
openSUSE Leap
Ubuntu
liblouis-bin (Ubuntu package)
liblouis9 (Ubuntu package)
python-louis (Ubuntu package)
liblouis20 (Ubuntu package)
python3-louis
liblouis-doc
liblouis
liblouis (Red Hat package)
liblouis-tools
liblouis-debuginfo
liblouis-tools-debuginfo
liblouis20-debuginfo
liblouis-devel
liblouis20
liblouis-debugsource
liblouis-data
dev-libs/liblouis

How to mitigate CVE-2023-26768

Install updates from vendor's website.

Liblouis - update to 3.25.0
liblouis-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 3.5.0-1ubuntu0.5, 3.12.0-3ubuntu0.2, 3.20.0-2ubuntu0.2, 3.22.0-2ubuntu0.1, 3.24.0-1ubuntu0.1
liblouis9 (Ubuntu package) - update to Ubuntu Pro
python-louis (Ubuntu package) - update to 3.5.0-1ubuntu0.5
liblouis20 (Ubuntu package) - addressed in versions 3.12.0-3ubuntu0.2, 3.20.0-2ubuntu0.2, 3.22.0-2ubuntu0.1, 3.24.0-1ubuntu0.1
python3-louis - update to 3.16.1-5
liblouis-doc - update to 3.16.1-5
liblouis - update to 3.16.1-5
liblouis (Red Hat package) - update to 3.16.1-5.el9
liblouis-doc - update to 3.20.0-150400.3.13.1
python3-louis - update to 3.20.0-150400.3.13.1
liblouis-tools - update to 3.20.0-150400.3.13.1
liblouis-debuginfo - update to 3.20.0-150400.3.13.1
liblouis-tools-debuginfo - update to 3.20.0-150400.3.13.1
liblouis20-debuginfo - update to 3.20.0-150400.3.13.1
liblouis-devel - update to 3.20.0-150400.3.13.1
liblouis20 - update to 3.20.0-150400.3.13.1
liblouis-debugsource - update to 3.20.0-150400.3.13.1
liblouis-data - update to 3.20.0-150400.3.13.1
dev-libs/liblouis - update to 3.25.0

External References

Related Security Bulletins