libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade aspell | Nov 27, 2019 | Oct 14, 2019 |
| Debian | — | Upgrade aspell | Oct 21, 2019 | Oct 14, 2019 |
| Oracle Solaris | — | Upgrade text/aspell to version 0.60.6.1-11.4.16.0.1.3.0 on Solaris 11.4Upgrade text/aspell/dictionary/en to version 0.60.6.1-11.4.16.0.1.3.0 on Solaris 11.4 | Dec 18, 2019 | Oct 14, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 14, 2019 |
| Suse | — | Upgrade aspell-develUpgrade libaspell15Upgrade libaspell15-32bitUpgrade aspellUpgrade libpspell15Upgrade aspell-ispell | Nov 22, 2019 | Oct 14, 2019 |
| Ubuntu | — | Upgrade aspellUpgrade aspell (Ubuntu Pro)Upgrade libaspell15Upgrade libaspell15 (Ubuntu Pro) | Oct 16, 2019 | Oct 14, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub