OESA-2021-1290
Dashboard / Vulnerabilities / OESA-2021-1290
Summary: aspell security update
Details: GNU Aspell is a spell checker intended to replace Ispell. It can be used as a library and spell checker. Its main feature is that it provides much better suggestions than other inspectors, including Ispell and Microsoft Word. It also has many other technical enhancements to Ispell, such as the use of shared memory to store dictionaries, and intelligent processing of personal dictionaries when multiple Aspell processes are opened at one time. Security Fix(es): libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.(CVE-2019-17544)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1290, https://nvd.nist.gov/vuln/detail/CVE-2019-17544
Affected packages
Package
Name: aspell
Purl: pkg:rpm/openEuler/aspell&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
