CVE-2014-8184
published 2019-08-02CVE-2014-8184: A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.55%
72.2th percentile
A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | liblouis | < liblouis 2.6.2-1 (bookworm) | liblouis 2.6.2-1 (bookworm) |
| liblouis | liblouis | — | — |
| liblouis | liblouis | >= 0 < 2.6.2-1 | 2.6.2-1 |
| liblouis | liblouis | >= 0 < 2.6.2-1 | 2.6.2-1 |
| liblouis | liblouis | >= 0 < 2.6.2-1 | 2.6.2-1 |
| liblouis | liblouis | >= 0 < 2.6.2-1 | 2.6.2-1 |
| liblouis | liblouis | >= 2.5.0 < 2.5.4 | 2.5.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Liblouis vulnerability
vendor_ubuntu·2017-11-06
CVE-2014-8184 Liblouis vulnerability
Title: Liblouis vulnerability
Summary: Liblouis could be made to crash or run programs as your login if it
opened a specially crafted file.
Raphael Sanchez Prudencio discovered that Liblouis incorrectly handled certain files.
If a user were tricked into opening a crafted file, an attacker could possibly use this
to cause a denial of service or potentially execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
liblouis: incomplete fix for CVE-2014-8184
vendor_redhat·2017-11-02·CVSS 7.8
CVE-2017-15101 [HIGH] CWE-121 liblouis: incomplete fix for CVE-2014-8184
liblouis: incomplete fix for CVE-2014-8184
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
A missing fix for one stack-based buffer overflow in findTable() for CVE-2014-8184 was discovered. An attacker could cause denial of service or potentially allow arbitrary code execution.
Red Hat
liblouis: stack-based buffer overflow in findTable()
vendor_redhat·2017-10-09·CVSS 7.8
CVE-2014-8184 [HIGH] CWE-121 liblouis: stack-based buffer overflow in findTable()
liblouis: stack-based buffer overflow in findTable()
A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.
Debian
CVE-2014-8184: liblouis - A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-base...
vendor_debian·2014·CVSS 7.8
CVE-2014-8184 [HIGH] CVE-2014-8184: liblouis - A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-base...
A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.
Scope: local
bookworm: resolved (fixed in 2.6.2-1)
bullseye: resolved (fixed in 2.6.2-1)
forky: resolved (fixed in 2.6.2-1)
sid: resolved (fixed in 2.6.2-1)
trixie: resolved (fixed in 2.6.2-1)
GHSA
GHSA-4v7c-4xff-r4v7: A vulnerability was found in liblouis, versions 2
ghsa_unreviewed·2022-05-17
CVE-2014-8184 [HIGH] CWE-119 GHSA-4v7c-4xff-r4v7: A vulnerability was found in liblouis, versions 2
A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.
OSV
CVE-2014-8184: A vulnerability was found in liblouis, versions 2
osv·2019-08-02·CVSS 7.8
CVE-2014-8184 [HIGH] CVE-2014-8184: A vulnerability was found in liblouis, versions 2
A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15101 liblouis: incomplete fix for CVE-2014-8184
bugzilla·2017-11-08·CVSS 7.8
CVE-2017-15101 [HIGH] CVE-2017-15101 liblouis: incomplete fix for CVE-2014-8184
CVE-2017-15101 liblouis: incomplete fix for CVE-2014-8184
Incomplete fix of CVE-2014-8184: one possible stack-based buffer overflow missed in CVE-2014-8184 fix.
Discussion:
Acknowledgments:
Name: Samuel Thibault
---
Proposed patch by Samuel Thibault: https://github.com/liblouis/liblouis/files/1439794/CVE-2014-8184-fix.txt
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:3384 https://access.redhat.com/errata/RHSA-2017:3384
Bugzilla
CVE-2014-8184 liblouis: stack-based buffer overflow in findTable()
bugzilla·2017-09-18·CVSS 7.8
CVE-2014-8184 [HIGH] CVE-2014-8184 liblouis: stack-based buffer overflow in findTable()
CVE-2014-8184 liblouis: stack-based buffer overflow in findTable()
A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.
Discussion:
Acknowledgments:
Name: Raphael Sanchez Prudencio (Red Hat)
---
Hi
Can you share details on this issue? Is upstream aware of the details?
I found only https://github.com/liblouis/liblouis/issues/425 asking Upstream on it.
Regards,
Salvatore
---
(In reply to Salvatore Bonaccorso from comment #5)
> Hi
>
> Can you share details on this issue? Is upstream aware of the details?
>
> I found only https://github.com/liblouis/liblouis/issues/425 asking Upstream
> on it.
>
> Regards
2019-08-02
Published