CVE-2017-13739

EUVD-2017-5256
There is a heap-based buffer overflow that causes a more than two thousand bytes out-of-bounds write in Liblouis 3.2.0, triggered in the function resolveSubtable() in compileTranslationTable.c. It will lead to denial of service or remote code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
Affected Products (NVD)
VendorProductVersion
liblouisliblouis
3.2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
liblouis
bookworm
3.24.0-1
fixed
bullseye
3.16.0-1
fixed
jessie
no-dsa
sid
3.31.0-2
fixed
trixie
3.31.0-2
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
liblouis
trusty
dne
xenial
Fixed 2.6.4-2ubuntu0.1
released
zesty
Fixed 3.0.0-3ubuntu0.2
released