Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 635360 (CVE-2017-13739, CVE-2017-13740, CVE-2017-13741, CVE-2017-13742, CVE-2017-13743, CVE-2017-13744) - <dev-libs/liblouis-3.10.0: Multiple vulnerabilities
Summary: <dev-libs/liblouis-3.10.0: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2017-13739, CVE-2017-13740, CVE-2017-13741, CVE-2017-13742, CVE-2017-13743, CVE-2017-13744
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B2 [noglsa cve]
Keywords:
Depends on: 661150
Blocks:
  Show dependency tree
 
Reported: 2017-10-24 20:17 UTC by GLSAMaker/CVETool Bot
Modified: 2019-09-01 00:39 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2017-10-24 20:17:53 UTC
CVE-2017-13739 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-13739):
  There is a heap-based buffer overflow that causes a more than two thousand
  bytes out-of-bounds write in Liblouis 3.2.0, triggered in the function
  resolveSubtable() in compileTranslationTable.c. It will lead to denial of
  service or remote code execution.