A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.
{
"binaries": [
{
"binary_name": "liblouis-bin",
"binary_version": "2.5.3-2ubuntu1.2"
},
{
"binary_name": "liblouis-data",
"binary_version": "2.5.3-2ubuntu1.2"
},
{
"binary_name": "liblouis-dev",
"binary_version": "2.5.3-2ubuntu1.2"
},
{
"binary_name": "liblouis2",
"binary_version": "2.5.3-2ubuntu1.2"
},
{
"binary_name": "python-louis",
"binary_version": "2.5.3-2ubuntu1.2"
},
{
"binary_name": "python3-louis",
"binary_version": "2.5.3-2ubuntu1.2"
}
],
"availability": "No subscription required"
}