Buffer Over-Read Vulnerability in GNU Aspell by GNU
CVE-2019-20433
9.1CRITICAL
What is CVE-2019-20433?
The GNU Aspell library, specifically libaspell.a, contains a buffer over-read vulnerability affecting versions prior to 0.60.8. This issue arises when using string encodings of ucs-2 or ucs-4, which can lead to unexpected behavior in applications. This vulnerability is exploitable when the encoding is incorrectly set externally, such as via the ASPELL_CONF environment variable, potentially allowing unauthorized access to sensitive data during operations.