First published: Wed Nov 08 2017(Updated: )
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/liblouis | <2.5.4 | 2.5.4 |
Liblouis | <2.5.4 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux server aus | =7.4 | |
redhat enterprise Linux server eus | =7.4 | |
redhat enterprise Linux server eus | =7.5 | |
redhat enterprise Linux workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15101 has a high severity level due to the potential for denial of service and arbitrary code execution.
CVE-2017-15101 affects liblouis versions before 2.5.4 in Red Hat systems.
To fix CVE-2017-15101, upgrade liblouis to version 2.5.4 or later.
CVE-2017-15101 may allow attackers to execute arbitrary code or cause a denial of service.
There are no known effective workarounds for CVE-2017-15101; updating the software is recommended.