CVE-2023-49991

Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.
Configurations

Configuration 1 (hide)

cpe:2.3:a:espeak-ng:espeak-ng:1.52:dev:*:*:*:*:*:*

History

19 Jan 2024, 04:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PZEBWPNKPAYJMIM3AS2RP3FL6FX3HS4/ -

10 Jan 2024, 03:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z5WW6RKHRWLEMCKCQ6UZCXWC5J7UWMUQ/ -

18 Dec 2023, 18:29

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 5.3

14 Dec 2023, 19:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:espeak-ng:espeak-ng:1.52:dev:*:*:*:*:*:*
References () https://github.com/espeak-ng/espeak-ng/issues/1825 - () https://github.com/espeak-ng/espeak-ng/issues/1825 - Exploit, Issue Tracking, Vendor Advisory
CWE CWE-787
First Time Espeak-ng espeak-ng
Espeak-ng
Summary
  • (es) Se descubrió que Espeak-ng 1.52-dev contiene un desbordamiento del búfer a través de la función CountVowelPosition en synthdata.c.

12 Dec 2023, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 14:15

Updated : 2024-01-19 04:15


NVD link : CVE-2023-49991

Mitre link : CVE-2023-49991

CVE.ORG link : CVE-2023-49991


JSON object : View

Products Affected

espeak-ng

  • espeak-ng
CWE
CWE-787

Out-of-bounds Write