First published: Wed Sep 06 2017(Updated: )
There is a use-after-free in the function compileBrailleIndicator() in compileTranslationTable.c in Liblouis 3.2.0 that will lead to a denial of service attack. Product bug: <a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED WONTFIX - There is an use-after-free in function compileBrailleIndicator() of liblouis." href="show_bug.cgi?id=1484332">https://bugzilla.redhat.com/show_bug.cgi?id=1484332</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Liblouis |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1488938 is categorized as high due to its potential for causing denial of service.
To fix REDHAT-BUG-1488938, upgrade to a patched version of Liblouis that addresses the use-after-free vulnerability.
REDHAT-BUG-1488938 affects versions of Liblouis 3.2.0 that are vulnerable to the identified use-after-free issue.
Currently, there are no recommended workarounds for REDHAT-BUG-1488938; upgrading is the best approach.
If you cannot upgrade due to constraints, monitor your systems closely for unusual activity and consider isolating affected installations.