CVE-2004-0548
Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.92%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or (2) "d" decompress option.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Affected
- gnu/aspell · gentoo/linux
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=108675120224531&w=2
- http://www.gentoo.org/security/en/glsa/glsa-200406-14.xmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.securityfocus.com/bid/10497
- http://marc.info/?l=bugtraq&m=108675120224531&w=2
- http://www.gentoo.org/security/en/glsa/glsa-200406-14.xmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.securityfocus.com/bid/10497
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.