CVE-2026-75820
Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-190
Desbordamiento o ajuste de enteros
Fecha de publicación:
06/10/2026
Última modificación:
06/10/2026
Descripción
*** Pendiente de traducción *** GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service.<br />
<br />
<br />
<br />
This issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3.
Impacto
Puntuación base 4.0
1.80
Gravedad 4.0
BAJA


