CVE-2004-0548: Buffer Overflow
Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or (2) "d" decompress option.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0548?
CVE-2004-0548 is classified as a high-severity vulnerability due to its potential for local users to execute arbitrary code.
How do I fix CVE-2004-0548?
To fix CVE-2004-0548, upgrade to a patched version of GNU Aspell that addresses the buffer overflow issues.
What systems are affected by CVE-2004-0548?
CVE-2004-0548 affects GNU Aspell version 0.50.5 and Gentoo Linux version 1.4.
Can CVE-2004-0548 be exploited remotely?
CVE-2004-0548 requires local access for exploitation, as it involves local user input through the word-list-compress functionality.
What actions should be taken if I have CVE-2004-0548 on my system?
If CVE-2004-0548 is present, it is recommended to immediately update your software and review user permissions to limit potential exploitation.