CVE-2017-15101: Buffer Overflow
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
Other sources
Incomplete fix of CVE-2014-8184: one possible stack-based buffer overflow missed in CVE-2014-8184 fix.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15101?
CVE-2017-15101 has a high severity level due to the potential for denial of service and arbitrary code execution.
Which software versions are affected by CVE-2017-15101?
CVE-2017-15101 affects liblouis versions before 2.5.4 in Red Hat systems.
How do I fix CVE-2017-15101?
To fix CVE-2017-15101, upgrade liblouis to version 2.5.4 or later.
What exploit risks are associated with CVE-2017-15101?
CVE-2017-15101 may allow attackers to execute arbitrary code or cause a denial of service.
Is there a known workaround for CVE-2017-15101?
There are no known effective workarounds for CVE-2017-15101; updating the software is recommended.