A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
{
"binaries": [
{
"binary_name": "liblouis-bin",
"binary_version": "2.5.3-2ubuntu1.2"
},
{
"binary_name": "liblouis-data",
"binary_version": "2.5.3-2ubuntu1.2"
},
{
"binary_name": "liblouis-dev",
"binary_version": "2.5.3-2ubuntu1.2"
},
{
"binary_name": "liblouis2",
"binary_version": "2.5.3-2ubuntu1.2"
},
{
"binary_name": "python-louis",
"binary_version": "2.5.3-2ubuntu1.2"
},
{
"binary_name": "python3-louis",
"binary_version": "2.5.3-2ubuntu1.2"
}
],
"availability": "No subscription required"
}