CVE-2019-25051
published 2021-07-20CVE-2019-25051: objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and…
high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | aspell | < aspell 0.60.8-3 (bookworm) | aspell 0.60.8-3 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| gnu | aspell | — | — |
| gnu | aspell | >= 0 < 0.60.8-3 | 0.60.8-3 |
| gnu | aspell | >= 0 < 0.60.8-3 | 0.60.8-3 |
| gnu | aspell | >= 0 < 0.60.8-3 | 0.60.8-3 |
| gnu | aspell | >= 0 < 0.60.8-3 | 0.60.8-3 |
| msrc | cbl2_aspell_0.60.8-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_aspell_0.60.8-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH