First published: Wed May 30 2018(Updated: )
Liblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Liblouis Liblouis | =3.5.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Canonical Ubuntu Linux | =18.04 | |
openSUSE Leap | =15.0 | |
ubuntu/liblouis | <3.0.0-3ubuntu1.1 | 3.0.0-3ubuntu1.1 |
ubuntu/liblouis | <3.5.0-1ubuntu0.1 | 3.5.0-1ubuntu0.1 |
ubuntu/liblouis | <2.5.3-2ubuntu1.3 | 2.5.3-2ubuntu1.3 |
ubuntu/liblouis | <2.6.4-2ubuntu0.2 | 2.6.4-2ubuntu0.2 |
debian/liblouis | 3.16.0-1 3.24.0-1 3.30.0-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11577 is a vulnerability in Liblouis 3.5.0 that can cause a Segmentation fault in lou_logPrint in logging.c.
The severity of CVE-2018-11577 is high, with a CVSS score of 8.8.
The affected software versions include Liblouis 3.5.0, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 17.10, and Ubuntu 18.04.
To fix CVE-2018-11577, you can update your Liblouis package to version 3.8.0-2, 3.16.0-1, 3.24.0-1, or 3.27.0-1. For Ubuntu, update to version 2.6.4-2ubuntu0.2 (xenial), 3.0.0-3ubuntu1.1 (artful), or 3.5.0-1ubuntu0.1 (bionic).
You can find more information about CVE-2018-11577 at the following references: [1](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00038.html), [2](https://github.com/Edward-L/fuzzing-pocs/tree/master/liblouis), [3](https://github.com/liblouis/liblouis/issues/582).