RLSA-2020:1708

Source
https://errata.rockylinux.org/RLSA-2020:1708
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2020:1708.json
JSON Data
https://api.osv.dev/v1/vulns/RLSA-2020:1708
Related
Published
2020-04-28T09:07:17Z
Modified
2023-02-02T13:05:07.807873Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Moderate: liblouis security and bug fix update
Details

Liblouis is an open source braille translator and back-translator named in honor of Louis Braille. It features support for computer and literary braille, supports contracted and uncontracted translation for many languages and has support for hyphenation. New languages can easily be added through tables that support a rule or dictionary based approach. Liblouis also supports math braille (Nemeth and Marburg).

Security Fix(es):

  • liblouis: Stack-based buffer overflow in function includeFile in compileTranslationTable.c (CVE-2018-11684)

  • liblouis: Stack-based buffer overflow in function compileHyphenation in compileTranslationTable.c (CVE-2018-11685)

  • liblouis: Segmentation fault in logging.c:lou_logPrint() (CVE-2018-11577)

  • liblouis: Stack-based buffer overflow in compileTranslationTable.c (CVE-2018-12085)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.2 Release Notes linked from the References section.

References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:8 / liblouis

Package

Name
liblouis
Purl
pkg:rpm/rocky-linux/liblouis?distro=rocky-linux-8&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:2.6.2-21.el8