CVE-2022-26981
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
13/03/2022
Last modified:
07/11/2023
Description
Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:liblouis:liblouis:*:*:*:*:*:*:*:* | 3.21.0 (including) | |
| cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
| cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | 15.6 (excluding) | |
| cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | 15.6 (excluding) | |
| cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | 12.0 (including) | 12.5 (excluding) |
| cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | 15.6 (excluding) | |
| cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* | 8.7 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://seclists.org/fulldisclosure/2022/Jul/12
- http://seclists.org/fulldisclosure/2022/Jul/15
- http://seclists.org/fulldisclosure/2022/Jul/16
- http://seclists.org/fulldisclosure/2022/Jul/18
- https://github.com/liblouis/liblouis/issues/1171
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CFD2KIHESDUCNWTEW3USFB5GKTWT624L/
- https://security.gentoo.org/glsa/202301-06
- https://support.apple.com/kb/HT213340
- https://support.apple.com/kb/HT213342
- https://support.apple.com/kb/HT213345
- https://support.apple.com/kb/HT213346



