MEDIUM
hunspell: out-of-bounds read in SuggestMgr::leftcommonsubstring in suggestmgr.cxx
Published Sep 23, 2019
6.5
MEDIUMCVSS 3.1
EPSS 1.65%
Description
Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx.
Affected products
No data.
Configuration 1
- 1.7.0
Configuration 2
OR
- 30
- 31
No data.
Red Hat Enterprise Linux 7
hunspell-0:1.3.2-16.el7
Fixed · RHSA-2020:3971
Red Hat Enterprise Linux 6
hunspell
Out of support scope
Red Hat Enterprise Linux 8
hunspell
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | hunspell-0:1.3.2-16.el7 | Fixed | RHSA-2020:3971 |
| Red Hat Enterprise Linux 6 | hunspell | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | hunspell | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is unlikely to be an issue in a real world scenario, as it requires specially crafted Hunspell dictionaries, which are not shipped with Red Hat Enterprise Linux. Additionally, applications using Hunspell will likely filter out invalid input before passing it on, which further limits the impact.
Weaknesses (2)
References (9)
- https://access.redhat.com/security/cve/CVE-2019-16707 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1771026 Issue Tracking
- https://github.com/butterflyhack/hunspell-crash x_refsource_MISCExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/24NTBHK2QNYKSBMJI34WEU5MHS3H2FAI/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D2YOYFI36IWKABNGFTWXCH7TTGAFODH6/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNTSVWI4SWBQL6XMXNGEH7EAQ45WN63G/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UD4AJ4M74VT3I6L37E4P5DNYZYBZIOVM/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-16707
- https://www.cve.org/CVERecord?id=CVE-2019-16707
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-16707 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1771026 | Issue Tracking | |
| https://github.com/butterflyhack/hunspell-crash | x_refsource_MISCExploitThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/24NTBHK2QNYKSBMJI34WEU5MHS3H2FAI/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D2YOYFI36IWKABNGFTWXCH7TTGAFODH6/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNTSVWI4SWBQL6XMXNGEH7EAQ45WN63G/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UD4AJ4M74VT3I6L37E4P5DNYZYBZIOVM/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-16707 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-16707 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 23, 2019
Updated Aug 5, 2024
Reserved Sep 23, 2019
Link CVE-2019-16707
CISA Vulnrichment
Updated n/a