CVE-2019-25051: Buffer Overflow
objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::duptop (called from acommon::StringMap::add and acommon::Config::lookuplist).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-25051?
CVE-2019-25051 is a vulnerability in GNU Aspell 0.60.8 that allows a heap-based buffer overflow in acommon::ObjStack::dup_top.
What is the severity rating of CVE-2019-25051?
CVE-2019-25051 has a severity rating of 7.8 (high).
How does CVE-2019-25051 affect GNU Aspell?
CVE-2019-25051 affects GNU Aspell 0.60.8 by allowing a heap-based buffer overflow in acommon::ObjStack::dup_top, which can be triggered from acommon::StringMap::add and acommon::Config::lookup_list.
Which software versions are affected by CVE-2019-25051?
CVE-2019-25051 affects GNU Aspell 0.60.8, Debian Debian Linux 9.0 and 10.0, and Fedora 34.
How can I fix the vulnerability CVE-2019-25051 in GNU Aspell?
To fix CVE-2019-25051 in GNU Aspell, you should update to one of the following versions: 0.60.7~20110707-6+deb10u1, 0.60.8-3, 0.60.8-4, 0.60.8-6.