Lucene search

K
cveMitreCVE-2004-0548
HistoryAug 06, 2004 - 4:00 a.m.

CVE-2004-0548

2004-08-0604:00:00
mitre
web.nvd.nist.gov
52
cve-2004-0548
aspell
buffer overflow
compress.c
word-list-compress
security vulnerability

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0

Percentile

0.4%

Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) “c” compress option or (2) “d” decompress option.

Affected configurations

Nvd
Node
gnuaspellMatch0.50.5
Node
gentoolinuxMatch1.4
VendorProductVersionCPE
gnuaspell0.50.5cpe:2.3:a:gnu:aspell:0.50.5:*:*:*:*:*:*:*
gentoolinux1.4cpe:2.3:o:gentoo:linux:1.4:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0

Percentile

0.4%