Bugzilla – Bug 1188576
VUL-0: CVE-2019-25051: aspell: heap-buffer-overflow in acommon:ObjStack:dup_top
Last modified: 2024-05-13 18:36:23 UTC
rh#1984066 objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list). References: https://github.com/gnuaspell/aspell/commit/0718b375425aad8e54e1150313b862e4c6fd324a https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=18462 https://github.com/google/oss-fuzz-vulns/blob/main/vulns/aspell/OSV-2020-521.yaml References: https://bugzilla.redhat.com/show_bug.cgi?id=1984066 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=18462 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-25051 http://www.cvedetails.com/cve/CVE-2019-25051/ https://github.com/google/oss-fuzz-vulns/blob/main/vulns/aspell/OSV-2020-521.yaml http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-25051 https://github.com/gnuaspell/aspell/commit/0718b375425aad8e54e1150313b862e4c6fd324a
Submitted for TW,12,11/aspell. I believe all fixed.
This is an autogenerated message for OBS integration: This bug (1188576) was mentioned in https://build.opensuse.org/request/show/909814 Factory / aspell
@Petr: our tracking also shows SUSE:SLE-15-SP2:Update/aspell as affected. Is this assessment incorrect ?
(In reply to Robert Frohl from comment #4) > @Petr: our tracking also shows SUSE:SLE-15-SP2:Update/aspell as affected. Is > this assessment incorrect ? Right. I was not expecting aspell in code 15.
Submitted for TW,15sp2,12,11/aspell. I believe all fixed.
SUSE-SU-2021:14783-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1188576 CVE References: CVE-2019-25051 JIRA References: Sources used: SUSE Linux Enterprise Server 11-SP4-LTSS (src): aspell-0.60.6-26.36.1 SUSE Linux Enterprise Point of Sale 11-SP3 (src): aspell-0.60.6-26.36.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): aspell-0.60.6-26.36.1 SUSE Linux Enterprise Debuginfo 11-SP3 (src): aspell-0.60.6-26.36.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
# maintenance_jira_update_notice SUSE-SU-2021:2794-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1177523,1188576 CVE References: CVE-2019-25051 JIRA References: Sources used: SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): aspell-0.60.8-3.3.1 SUSE Linux Enterprise Module for Basesystem 15-SP2 (src): aspell-0.60.8-3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
# maintenance_jira_update_notice openSUSE-SU-2021:2794-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1177523,1188576 CVE References: CVE-2019-25051 JIRA References: Sources used: openSUSE Leap 15.3 (src): aspell-0.60.8-3.3.1
# maintenance_jira_update_notice openSUSE-SU-2021:1181-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1177523,1188576 CVE References: CVE-2019-25051 JIRA References: Sources used: openSUSE Leap 15.2 (src): aspell-0.60.8-lp152.2.3.1
# maintenance_jira_update_notice SUSE-SU-2021:2848-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1188576 CVE References: CVE-2019-25051 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 9 (src): aspell-0.60.6.1-18.11.1 SUSE OpenStack Cloud Crowbar 8 (src): aspell-0.60.6.1-18.11.1 SUSE OpenStack Cloud 9 (src): aspell-0.60.6.1-18.11.1 SUSE OpenStack Cloud 8 (src): aspell-0.60.6.1-18.11.1 SUSE Linux Enterprise Software Development Kit 12-SP5 (src): aspell-0.60.6.1-18.11.1 SUSE Linux Enterprise Server for SAP 12-SP4 (src): aspell-0.60.6.1-18.11.1 SUSE Linux Enterprise Server for SAP 12-SP3 (src): aspell-0.60.6.1-18.11.1 SUSE Linux Enterprise Server 12-SP5 (src): aspell-0.60.6.1-18.11.1 SUSE Linux Enterprise Server 12-SP4-LTSS (src): aspell-0.60.6.1-18.11.1 SUSE Linux Enterprise Server 12-SP3-LTSS (src): aspell-0.60.6.1-18.11.1 SUSE Linux Enterprise Server 12-SP3-BCL (src): aspell-0.60.6.1-18.11.1 SUSE Linux Enterprise Server 12-SP2-BCL (src): aspell-0.60.6.1-18.11.1 HPE Helion Openstack 8 (src): aspell-0.60.6.1-18.11.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.