Skip to content

Conversation

@npt-1707
Copy link
Contributor

@npt-1707 npt-1707 commented Dec 19, 2025

Summary

Our tool detected a potential out-of-bound read vulnerability in unescape() in src/Emulators/vice/monitor/mon_lex.c which was cloned from GNUAspell/aspell@80fa26c but did not receive the security patch. The original issue was reported and fixed under CVE-2019-17544.

Proposed Fix

Apply the same patch to eliminate the vulnerability.

Reference

https://nvd.nist.gov/vuln/detail/CVE-2019-17544
GNUAspell/aspell@80fa26c

@slajerek slajerek merged commit d61c6b1 into slajerek:master Dec 19, 2025
@npt-1707
Copy link
Contributor Author

Hi @slajerek,

Just want to let you know that we plan to submit a CVE for this issue. Please let us know if you have any concerns. Many thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants