CVE-2019-16707 Information
Feb 14, 2021
cve
Description
Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Reference
https://github.com/butterflyhack/hunspell-crash https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/24NTBHK2QNYKSBMJI34WEU5MHS3H2FAI/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2YOYFI36IWKABNGFTWXCH7TTGAFODH6/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNTSVWI4SWBQL6XMXNGEH7EAQ45WN63G/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UD4AJ4M74VT3I6L37E4P5DNYZYBZIOVM/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
6.5
Share on: