CVE-2023-26767

Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the lou_logFile function at logginc.c endpoint.
References
Link Resource
https://github.com/liblouis/liblouis/issues/1292 Exploit Issue Tracking Patch
https://github.com/liblouis/liblouis/pull/1297 Issue Tracking Patch
Configurations

Configuration 1 (hide)

cpe:2.3:a:liblouis:liblouis:3.24.0:*:*:*:*:*:*:*

History

22 Mar 2023, 02:01

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:liblouis:liblouis:3.24.0:*:*:*:*:*:*:*
CWE CWE-120
References (MISC) https://github.com/liblouis/liblouis/pull/1297 - (MISC) https://github.com/liblouis/liblouis/pull/1297 - Issue Tracking, Patch
References (MISC) https://github.com/liblouis/liblouis/issues/1292 - (MISC) https://github.com/liblouis/liblouis/issues/1292 - Exploit, Issue Tracking, Patch
First Time Liblouis
Liblouis liblouis

16 Mar 2023, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-16 15:15

Updated : 2023-12-10 14:48


NVD link : CVE-2023-26767

Mitre link : CVE-2023-26767

CVE.ORG link : CVE-2023-26767


JSON object : View

Products Affected

liblouis

  • liblouis
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')