CVE-2022-26981Classic Buffer Overflow in Liblouis

Severity
7.8HIGHNVD
EPSS
0.4%
top 41.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateJul 20

Description

Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages8 packages

Debianliblouis/liblouis< 3.22.0-1+2
Ubuntuliblouis/liblouis< 3.5.0-1ubuntu0.4+2
NVDliblouis/liblouis3.21.0
NVDapple/tvos< 15.6
NVDapple/macos12.012.5

Also affects: Fedora 36

Patches

🔴Vulnerability Details

4
OSV
liblouis vulnerabilities2022-06-13
GHSA
GHSA-xrp8-mw8v-p6mq: Liblouis through 32022-03-14
OSV
CVE-2022-26981: Liblouis through 32022-03-13
CVEList
CVE-2022-26981: Liblouis through 32022-03-13

📋Vendor Advisories

7
Apple
CVE-2022-26981: tvOS 15.62022-07-20
Apple
CVE-2022-26981: watchOS 8.72022-07-20
Apple
CVE-2022-26981: iOS 15.6 and iPadOS 15.62022-07-20
Apple
CVE-2022-26981: macOS Monterey 12.52022-07-20
Ubuntu
Liblouis vulnerabilities2022-06-13
CVE-2022-26981 — Classic Buffer Overflow in Liblouis | cvebase