OpenBSD VuXML: Documenting security issues in the OpenBSD Ports & Packages Collection

aspell -- buffer overflow in word-list-compress

Affected packages
aspell < 0.50.5p1

Details

VuXML ID 6b90f21a-c246-11d8-b7bd-00304f19272c
Discovery 2004-06-08
Entry 2004-06-19

aspell includes a utility for handling wordlists called word-list-compress. This utility fails to do proper bounds checking when processing words longer than 256 bytes. If an attacker could entice a user to handle a wordlist containing very long word lengths it could result in the execution of arbitrary code with the permissions of the user running the program.

References

URL http://nettwerked.mg2.org/advisories/wlc