GNU Aspell is a spell checker intended to replace Ispell. It can be used as a library and spell checker. Its main feature is that it provides much better suggestions than other inspectors, including Ispell and Microsoft Word. It also has many other technical enhancements to Ispell, such as the use of shared memory to store dictionaries, and intelligent processing of personal dictionaries when multiple Aspell processes are opened at one time.
Security Fix(es):
libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encoding is set to ucs-2 or ucs-4 outside of the application, as demonstrated by the ASPELL_CONF environment variable.(CVE-2019-20433)
{ "severity": "Medium" }
{ "x86_64": [ "aspell-debuginfo-0.60.6.1-29.oe1.x86_64.rpm", "aspell-devel-0.60.6.1-29.oe1.x86_64.rpm", "aspell-help-0.60.6.1-29.oe1.x86_64.rpm", "aspell-debugsource-0.60.6.1-29.oe1.x86_64.rpm", "aspell-0.60.6.1-29.oe1.x86_64.rpm" ], "aarch64": [ "aspell-help-0.60.6.1-29.oe1.aarch64.rpm", "aspell-devel-0.60.6.1-29.oe1.aarch64.rpm", "aspell-debugsource-0.60.6.1-29.oe1.aarch64.rpm", "aspell-debuginfo-0.60.6.1-29.oe1.aarch64.rpm", "aspell-0.60.6.1-29.oe1.aarch64.rpm" ], "src": [ "aspell-0.60.6.1-29.oe1.src.rpm" ] }
{ "x86_64": [ "aspell-0.60.6.1-29.oe1.x86_64.rpm", "aspell-debuginfo-0.60.6.1-29.oe1.x86_64.rpm", "aspell-devel-0.60.6.1-29.oe1.x86_64.rpm", "aspell-debugsource-0.60.6.1-29.oe1.x86_64.rpm", "aspell-help-0.60.6.1-29.oe1.x86_64.rpm" ], "aarch64": [ "aspell-debuginfo-0.60.6.1-29.oe1.aarch64.rpm", "aspell-devel-0.60.6.1-29.oe1.aarch64.rpm", "aspell-0.60.6.1-29.oe1.aarch64.rpm", "aspell-help-0.60.6.1-29.oe1.aarch64.rpm", "aspell-debugsource-0.60.6.1-29.oe1.aarch64.rpm" ], "src": [ "aspell-0.60.6.1-29.oe1.src.rpm" ] }