CVE-2017-13739

There is a heap-based buffer overflow that causes a more than two thousand bytes out-of-bounds write in Liblouis 3.2.0, triggered in the function resolveSubtable() in compileTranslationTable.c. It will lead to denial of service or remote code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
liblouisliblouis
3.2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
liblouis
bullseye
3.16.0-1
fixed
jessie
no-dsa
wheezy
not-affected
bookworm
3.24.0-1
fixed
sid
3.31.0-2
fixed
trixie
3.31.0-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
liblouis
zesty
Fixed 3.0.0-3ubuntu0.2
released
xenial
Fixed 2.6.4-2ubuntu0.1
released
trusty
dne