CVE-2019-17544: Critical severity GNU aspell vulnerability
Published Oct 14, 2019
·Updated
Last updated 25 August 2025
Other sources
libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.
— Launchpad
Affected Software
7 affected componentsFixes available
GNU aspell<0.60.8
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.04
debian/aspell
0.60.8-30.60.8-40.60.8.1-40.60.8.2-3
Remediation
Event History
Oct 14, 2019
CVE Published
via MITRE·01:07 AM
Data Sourced
via MITRE·01:07 AM
Description
Data Sourced
via NVD·02:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:23 PM
Description
Feb 21, 2026
Data Sourced
via Ubuntu·12:13 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·12:14 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-17544?
The severity of CVE-2019-17544 is critical with a severity value of 9.1.
2
How does CVE-2019-17544 affect GNU Aspell?
CVE-2019-17544 affects GNU Aspell before version 0.60.8.
3
How can I fix CVE-2019-17544 on Debian?
To fix CVE-2019-17544 on Debian, update the aspell package to version 0.60.8 or later.
4
How can I fix CVE-2019-17544 on Ubuntu?
To fix CVE-2019-17544 on Ubuntu, update the aspell package to the specified remedy version for your Ubuntu version.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-17544?
The Common Weakness Enumeration (CWE) ID for CVE-2019-17544 is CWE-125.