yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2019-25051
Component Overview
Vulnerability Overview
Name
CVE-2019-25051
Source
NVD (
link
)
Debian (
link
)
Description
objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).
CWEs
CWE-787
Published Date
Jul 20, 2021
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=18462
Third Party Advisory
https://github.com/gnuaspell/aspell/commit/0718b375425aad8e54e1150313b862e4c6fd324a
Patch
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/aspell/OSV-2020-521.yaml
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/07/msg00021.html
Mailing List
https://www.debian.org/security/2021/dsa-4948
Third Party Advisory
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=18462
Third Party Advisory
https://github.com/gnuaspell/aspell/commit/0718b375425aad8e54e1150313b862e4c6fd324a
Patch
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/aspell/OSV-2020-521.yaml
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/07/msg00021.html
Mailing List
https://www.debian.org/security/2021/dsa-4948
Third Party Advisory
Analysis
#
Affected Component
Analysis
aspell
Exploitable
Vulnerability Ratings
#
7.8
CVSSv31
4.6
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
aspell
yocto
master
0.60.8.2
Not Affected
aspell
yocto
scarthgap
0.60.8.1
Not Affected