OESA-2024-1057
Dashboard / Vulnerabilities / OESA-2024-1057
OESA-2024-1057
Summary: espeak-ng security update
Details: The eSpeak NG is a compact open source software text-to-speech synthesizer for Linux, Windows, Android and other operating systems. It supports 70 languages and accents. It is based on the eSpeak engine created by Jonathan Duddington. Security Fix(es): Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.(CVE-2023-49990) Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.(CVE-2023-49991) Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c.(CVE-2023-49992) Espeak-ng 1.52-dev was discovered to contain a Buffer Overflow via the function ReadClause at readclause.c.(CVE-2023-49993) Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.(CVE-2023-49994)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1057, https://nvd.nist.gov/vuln/detail/CVE-2023-49990, https://nvd.nist.gov/vuln/detail/CVE-2023-49991, https://nvd.nist.gov/vuln/detail/CVE-2023-49992, https://nvd.nist.gov/vuln/detail/CVE-2023-49993, https://nvd.nist.gov/vuln/detail/CVE-2023-49994
Affected packages
Package
Name: espeak-ng
Purl: pkg:rpm/openEuler/espeak-ng&distro=openEuler-22.03-LTS-SP3
Affected ranges
Type: ECOSYSTEM
Events:
