Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a long string, as demonstrated by the gplotRead and ptaReadStream functions.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade leptonlib | Feb 25, 2019 | Feb 16, 2018 |
| Gentoo Linux | — | Upgrade media-libs/leptonica. | Dec 19, 2023 | Feb 16, 2018 |
| Suse | — | Upgrade liblept4-debuginfo-32bitUpgrade leptonica-toolsUpgrade leptonica-develUpgrade leptonica-debugsourceUpgrade liblept4-32bitUpgrade liblept4Upgrade liblept4-debuginfoUpgrade leptonica-tools-debuginfo | Mar 10, 2018 | Feb 16, 2018 |
| Ubuntu | — | Upgrade liblept4 (Ubuntu Pro)Upgrade liblept5 (Ubuntu Pro) | Mar 22, 2023 | Feb 16, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub