CVE-2023-49992

NameCVE-2023-49992
DescriptionEspeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1059060

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
espeak-ng (PTS)buster1.49.2+dfsg-8+deb10u1vulnerable
bullseye1.50+dfsg-7+deb11u1vulnerable
bookworm1.51+dfsg-10+deb12u1fixed
trixie, sid1.51+dfsg-12fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
espeak-ngsourcebookworm1.51+dfsg-10+deb12u1
espeak-ngsource(unstable)1.51+dfsg-121059060

Notes

[bullseye] - espeak-ng <no-dsa> (Minor issue)
[buster] - espeak-ng <no-dsa> (Minor issue)
https://github.com/espeak-ng/espeak-ng/issues/1827
https://github.com/espeak-ng/espeak-ng/commit/58f1e0b6a4e6aa55621c6f01118994d01fd6f68c

Search for package or bug name: Reporting problems