GNU Aspell 中存在一个整数截断漏洞,位于 中的 函数内。当加载个人词表时,单词长度被存储为单个字节,导致长度为 256 倍数的单词发生截断。这引发了堆损坏。攻击者可通过诱使用户使用包含此类单词的恶意构造的个人词表运行 aspell,从而利用该漏洞导致拒绝服务(DoS)。 该问题已在提交 中修复,并将在版本 中发布。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75819 | 1.8 LOW | Out-of-bounds Read in GNU Aspell |
| CVE-2026-75818 | 1.8 LOW | Heap Buffer Overflow in GNU Aspell's prezip utility |
No comments yet