CVE-2022-26981
published 2022-03-13CVE-2022-26981: Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.46%
70.6th percentile
Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.6_and_ipados | — | — |
| apple | ipados | < 15.6 | 15.6 |
| apple | iphone_os | < 15.6 | 15.6 |
| apple | macos | >= 12.0 < 12.5 | 12.5 |
| apple | macos_monterey | — | — |
| apple | tvos | < 15.6 | 15.6 |
| apple | tvos | — | — |
| apple | watchos | < 8.7 | 8.7 |
| apple | watchos | — | — |
| debian | liblouis | < liblouis 3.22.0-1 (bookworm) | liblouis 3.22.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| liblouis | liblouis | <= 3.21.0 | — |
| liblouis | liblouis | >= 0 < 3.22.0-1 | 3.22.0-1 |
| liblouis | liblouis | >= 0 < 3.22.0-1 | 3.22.0-1 |
| liblouis | liblouis | >= 0 < 3.22.0-1 | 3.22.0-1 |
| liblouis | liblouis | >= 0 < 3.5.0-1ubuntu0.4 | 3.5.0-1ubuntu0.4 |
| liblouis | liblouis | >= 0 < 3.12.0-3ubuntu0.1 | 3.12.0-3ubuntu0.1 |
| liblouis | liblouis | >= 0 < 3.20.0-2ubuntu0.1 | 3.20.0-2ubuntu0.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-26981: tvOS 15.6
vendor_apple·2022-07-20·CVSS 7.8
CVE-2022-26981 [HIGH] CVE-2022-26981: tvOS 15.6
Apple Security Update: About the security content of tvOS 15.6
Product: tvOS
Version: 15.6
CVE: CVE-2022-26981
Component: Liblouis
Impact: An app may cause unexpected app termination or arbitrary code execution
Description: This issue was addressed with improved checks.
Apple
CVE-2022-26981: watchOS 8.7
vendor_apple·2022-07-20·CVSS 7.8
CVE-2022-26981 [HIGH] CVE-2022-26981: watchOS 8.7
Apple Security Update: About the security content of watchOS 8.7
Product: watchOS
Version: 8.7
CVE: CVE-2022-26981
Component: Liblouis
Impact: An app may cause unexpected app termination or arbitrary code execution
Description: This issue was addressed with improved checks.
Apple
CVE-2022-26981: iOS 15.6 and iPadOS 15.6
vendor_apple·2022-07-20·CVSS 7.8
CVE-2022-26981 [HIGH] CVE-2022-26981: iOS 15.6 and iPadOS 15.6
Apple Security Update: About the security content of iOS 15.6 and iPadOS 15.6
Product: iOS 15.6 and iPadOS
Version: 15.6
CVE: CVE-2022-26981
Component: Liblouis
Impact: An app may cause unexpected app termination or arbitrary code execution
Description: This issue was addressed with improved checks.
Apple
CVE-2022-26981: macOS Monterey 12.5
vendor_apple·2022-07-20·CVSS 7.8
CVE-2022-26981 [HIGH] CVE-2022-26981: macOS Monterey 12.5
Apple Security Update: About the security content of macOS Monterey 12.5
Product: macOS Monterey
Version: 12.5
CVE: CVE-2022-26981
Component: Liblouis
Impact: An app may cause unexpected app termination or arbitrary code execution
Description: This issue was addressed with improved checks.
Ubuntu
Liblouis vulnerabilities
vendor_ubuntu·2022-06-13·CVSS 7.8
CVE-2022-31783 [HIGH] Liblouis vulnerabilities
Title: Liblouis vulnerabilities
Summary: Several security issues were fixed in liblouis.
Han Zheng discovered that Liblouis incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash. This issue was
addressed in Ubuntu 21.10 and Ubuntu 22.04 LTS. (CVE-2022-26981)
It was discovered that Liblouis incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code
or cause a crash. (CVE-2022-31783)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
liblouis: buffer overflow in compilePassOpcode
vendor_redhat·2022-03-13·CVSS 7.8
CVE-2022-26981 [HIGH] CWE-119 liblouis: buffer overflow in compilePassOpcode
liblouis: buffer overflow in compilePassOpcode
Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
A vulnerability was found in liblouis. This flaw allows an attacker to exploit the compilePassOpcode function, causing a buffer overflow.
Package: liblouis (Red Hat Enterprise Linux 7) - Out of support scope
Package: liblouis (Red Hat Enterprise Linux 8) - Fix deferred
Package: liblouis (Red Hat Enterprise Linux 9) - Fix deferred
Debian
CVE-2022-26981: liblouis - Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTra...
vendor_debian·2022·CVSS 7.8
CVE-2022-26981 [HIGH] CVE-2022-26981: liblouis - Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTra...
Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
Scope: local
bookworm: resolved (fixed in 3.22.0-1)
bullseye: open
forky: resolved (fixed in 3.22.0-1)
sid: resolved (fixed in 3.22.0-1)
trixie: resolved (fixed in 3.22.0-1)
OSV
liblouis vulnerabilities
osv·2022-06-13·CVSS 7.8
CVE-2022-26981 [HIGH] liblouis vulnerabilities
liblouis vulnerabilities
Han Zheng discovered that Liblouis incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash. This issue was
addressed in Ubuntu 21.10 and Ubuntu 22.04 LTS. (CVE-2022-26981)
It was discovered that Liblouis incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code
or cause a crash. (CVE-2022-31783)
GHSA
GHSA-xrp8-mw8v-p6mq: Liblouis through 3
ghsa_unreviewed·2022-03-14
CVE-2022-26981 [HIGH] CWE-120 GHSA-xrp8-mw8v-p6mq: Liblouis through 3
Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
OSV
CVE-2022-26981: Liblouis through 3
osv·2022-03-13·CVSS 7.8
CVE-2022-26981 [HIGH] CVE-2022-26981: Liblouis through 3
Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2022/Jul/12http://seclists.org/fulldisclosure/2022/Jul/15http://seclists.org/fulldisclosure/2022/Jul/16http://seclists.org/fulldisclosure/2022/Jul/18https://github.com/liblouis/liblouis/issues/1171https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CFD2KIHESDUCNWTEW3USFB5GKTWT624L/https://security.gentoo.org/glsa/202301-06https://support.apple.com/kb/HT213340https://support.apple.com/kb/HT213342https://support.apple.com/kb/HT213345https://support.apple.com/kb/HT213346http://seclists.org/fulldisclosure/2022/Jul/12http://seclists.org/fulldisclosure/2022/Jul/15http://seclists.org/fulldisclosure/2022/Jul/16http://seclists.org/fulldisclosure/2022/Jul/18https://github.com/liblouis/liblouis/issues/1171https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CFD2KIHESDUCNWTEW3USFB5GKTWT624L/https://security.gentoo.org/glsa/202301-06https://support.apple.com/kb/HT213340https://support.apple.com/kb/HT213342https://support.apple.com/kb/HT213345https://support.apple.com/kb/HT213346
2022-03-13
Published