Bug#880621: liblouis: CVE-2014-8184: stack-based buffer overflow in findTable()

Salvatore Bonaccorso carnil at debian.org
Thu Nov 2 21:21:03 UTC 2017


Source: liblouis
Version: 2.5.1-1
Severity: important
Tags: patch security upstream fixed-upstream
Control: fixed -1 2.6.2-1

Hi,

the following vulnerability was published for liblouis. The issue is
actually already fixed upstream quite a while ago, see the references.
The purpose of this bug is to try to be able to track an isolated fix
for jessie (Think this can go via a point release)

CVE-2014-8184[0]:
stack-based buffer overflow in findTable()

It as reported first at [1], see [2] which contains as well the
isolated patch which was applied by Red Hat.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2014-8184
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8184
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1492701
[2] https://github.com/liblouis/liblouis/issues/425

Regards,
Salvatore



More information about the Pkg-a11y-devel mailing list