CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
Percentile
0.4%
Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) “c” compress option or (2) “d” decompress option.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 12 | all | aspell | < 0.50.5-3 | aspell_0.50.5-3_all.deb |
Debian | 11 | all | aspell | < 0.50.5-3 | aspell_0.50.5-3_all.deb |
Debian | 999 | all | aspell | < 0.50.5-3 | aspell_0.50.5-3_all.deb |
Debian | 13 | all | aspell | < 0.50.5-3 | aspell_0.50.5-3_all.deb |