Back

MEDIUM

liblouis: Stack-based buffer over-read in matchCurrentInput function lou_translateString.c

Published Sep 21, 2018

Description

The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via out-of-bounds read) by crafting an input file with certain translation dictionaries.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 21, 2018
Updated Aug 5, 2024
Reserved Sep 21, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 24, 2018