CVE-2023-49991: Medium severity red hat speech-dispatcher-espeak-ng vulnerability
Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49991?
CVE-2023-49991 is classified as a moderate severity vulnerability due to the stack buffer underflow it introduces.
How do I fix CVE-2023-49991?
To fix CVE-2023-49991, you should upgrade to the patched versions of espeak-ng which are 1.49.2+dfsg-1ubuntu0.1~ or higher for Ubuntu or 1.51+dfsg-12 for Debian.
What is affected by CVE-2023-49991?
CVE-2023-49991 affects espeak-ng version 1.52-dev specifically.
Can CVE-2023-49991 lead to code execution?
While CVE-2023-49991 is a buffer underflow issue, it typically does not directly lead to arbitrary code execution but could potentially be exploited in a controlled environment.
Where can I find more information about CVE-2023-49991?
For more information on CVE-2023-49991, you can refer to the relevant package release notes or advisories from your Linux distribution.