VYPR

rpm package

suse/aspell&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP5

pkg:rpm/suse/aspell&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5

Vulnerabilities (3)

  • CVE-2019-25051Jul 20, 2021
    affected < 0.60.6.1-18.11.1fixed 0.60.6.1-18.11.1

    objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).

  • CVE-2019-20433Jan 27, 2020
    affected < 0.60.6.1-18.8.2fixed 0.60.6.1-18.8.2

    libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encoding is set to ucs-2 or ucs-4 outside of the application, as demonstrated by the ASPELL_CONF environment variable.

  • CVE-2019-17544Oct 14, 2019
    affected < 0.60.6.1-18.3.1fixed 0.60.6.1-18.3.1

    libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.