PublicDateAtUSN: 2014-12-31 Candidate: CVE-2014-8184 PublicDate: 2019-08-02 13:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8184 https://bugzilla.redhat.com/show_bug.cgi?id=1492701 https://github.com/liblouis/liblouis/issues/425 https://ubuntu.com/security/notices/USN-3474-1 Description: A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened. Ubuntu-Description: Notes: leosilva> according to rhel notes it affects only old versions of liblouis leosilva> before 2.5.4. In our case it affects only trusty. Bugs: Priority: medium Discovered-by: Raphael Sanchez Prudencio Assigned-to: leosilva CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_liblouis: other: https://github.com/liblouis/liblouis/commit/dc97ef791a4fae9da11592c79f9f79e010596e0c#diff-7ade83431f79d2120c82012aee3b05c9L4524 upstream_liblouis: released (2.5.4) precise/esm_liblouis: DNE trusty_liblouis: released (2.5.3-2ubuntu1.2) trusty/esm_liblouis: DNE (trusty was released [2.5.3-2ubuntu1.2]) vivid/ubuntu-core_liblouis: DNE xenial_liblouis: not-affected (2.6.4-2ubuntu0.1) esm-infra/xenial_liblouis: not-affected (2.6.4-2ubuntu0.1) zesty_liblouis: not-affected (3.0.0-3ubuntu0.2) artful_liblouis: not-affected (3.0.0-3ubuntu1) devel_liblouis: not-affected (3.3.0-1)