CVE-2023-49990

Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.
Configurations

Configuration 1 (hide)

cpe:2.3:a:espeak-ng:espeak-ng:1.52:dev:*:*:*:*:*:*

History

19 Jan 2024, 04:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PZEBWPNKPAYJMIM3AS2RP3FL6FX3HS4/ -

10 Jan 2024, 03:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z5WW6RKHRWLEMCKCQ6UZCXWC5J7UWMUQ/ -

18 Dec 2023, 18:29

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 5.3

14 Dec 2023, 19:20

Type Values Removed Values Added
Summary
  • (es) Se descubrió que Espeak-ng 1.52-dev contenía un desbordamiento del búfer a través de la función SetUpPhonemeTable en synthdata.c.
References () https://github.com/espeak-ng/espeak-ng/issues/1824 - () https://github.com/espeak-ng/espeak-ng/issues/1824 - Exploit, Issue Tracking, Vendor Advisory
First Time Espeak-ng espeak-ng
Espeak-ng
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-120
CPE cpe:2.3:a:espeak-ng:espeak-ng:1.52:dev:*:*:*:*:*:*

12 Dec 2023, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 14:15

Updated : 2024-01-19 04:15


NVD link : CVE-2023-49990

Mitre link : CVE-2023-49990

CVE.ORG link : CVE-2023-49990


JSON object : View

Products Affected

espeak-ng

  • espeak-ng
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')