There is a heap-based buffer overflow that causes a more than two thousand bytes out-of-bounds write in Liblouis 3.2.0, triggered in the function resolveSubtable() in compileTranslationTable.c. It will lead to denial of service or remote code execution.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade liblouis | Jul 30, 2024 | Aug 29, 2017 |
| Oracle Solaris | — | Upgrade library/liblouis to version 2.1.1-0.175.3.35.0.3.0 on Solaris 11.3 | Aug 24, 2018 | Aug 29, 2017 |
| Suse | — | Upgrade liblouis0Upgrade liblouis9Upgrade liblouis-dataUpgrade python3-louisUpgrade liblouis14Upgrade python-louisUpgrade liblouis-develUpgrade liblouis19Upgrade liblouis | Sep 26, 2017 | Aug 29, 2017 |
| Ubuntu | — | Upgrade python-louisUpgrade liblouis9Upgrade liblouis-binUpgrade liblouis12Upgrade python3-louisUpgrade liblouis2 | Sep 4, 2017 | Aug 29, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub