CVE-2023-49990

NameCVE-2023-49990
DescriptionEspeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1059060

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
espeak-ng (PTS)bullseye1.50+dfsg-7+deb11u1vulnerable
bookworm1.51+dfsg-10+deb12u1fixed
sid, trixie1.52.0+dfsg-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
espeak-ngsourcebookworm1.51+dfsg-10+deb12u1
espeak-ngsource(unstable)1.51+dfsg-121059060

Notes

[bullseye] - espeak-ng <no-dsa> (Minor issue)
[buster] - espeak-ng <no-dsa> (Minor issue)
https://github.com/espeak-ng/espeak-ng/issues/1824
https://github.com/espeak-ng/espeak-ng/commit/58f1e0b6a4e6aa55621c6f01118994d01fd6f68c

Search for package or bug name: Reporting problems