OESA-2021-1290

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1290
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2021-1290.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2021-1290
Upstream
Published
2021-07-31T11:03:05Z
Modified
2025-08-12T05:04:29.949578Z
Summary
aspell security update
Details

GNU Aspell is a spell checker intended to replace Ispell. It can be used as a library and spell checker. Its main feature is that it provides much better suggestions than other inspectors, including Ispell and Microsoft Word. It also has many other technical enhancements to Ispell, such as the use of shared memory to store dictionaries, and intelligent processing of personal dictionaries when multiple Aspell processes are opened at one time.

Security Fix(es):

libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.(CVE-2019-17544)

Database specific
{
    "severity": "Critical"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / aspell

Package

Name
aspell
Purl
pkg:rpm/openEuler/aspell&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.60.6.1-27.oe1

Ecosystem specific

{
    "src": [
        "aspell-0.60.6.1-27.oe1.src.rpm"
    ],
    "x86_64": [
        "aspell-debugsource-0.60.6.1-27.oe1.x86_64.rpm",
        "aspell-0.60.6.1-27.oe1.x86_64.rpm",
        "aspell-debuginfo-0.60.6.1-27.oe1.x86_64.rpm",
        "aspell-help-0.60.6.1-27.oe1.x86_64.rpm",
        "aspell-devel-0.60.6.1-27.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "aspell-debugsource-0.60.6.1-27.oe1.aarch64.rpm",
        "aspell-0.60.6.1-27.oe1.aarch64.rpm",
        "aspell-devel-0.60.6.1-27.oe1.aarch64.rpm",
        "aspell-help-0.60.6.1-27.oe1.aarch64.rpm",
        "aspell-debuginfo-0.60.6.1-27.oe1.aarch64.rpm"
    ]
}

openEuler:20.03-LTS-SP2 / aspell

Package

Name
aspell
Purl
pkg:rpm/openEuler/aspell&distro=openEuler-20.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.60.6.1-27.oe1

Ecosystem specific

{
    "src": [
        "aspell-0.60.6.1-27.oe1.src.rpm"
    ],
    "x86_64": [
        "aspell-0.60.6.1-27.oe1.x86_64.rpm",
        "aspell-devel-0.60.6.1-27.oe1.x86_64.rpm",
        "aspell-help-0.60.6.1-27.oe1.x86_64.rpm",
        "aspell-debuginfo-0.60.6.1-27.oe1.x86_64.rpm",
        "aspell-debugsource-0.60.6.1-27.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "aspell-debuginfo-0.60.6.1-27.oe1.aarch64.rpm",
        "aspell-devel-0.60.6.1-27.oe1.aarch64.rpm",
        "aspell-debugsource-0.60.6.1-27.oe1.aarch64.rpm",
        "aspell-help-0.60.6.1-27.oe1.aarch64.rpm",
        "aspell-0.60.6.1-27.oe1.aarch64.rpm"
    ]
}