This issue was fixed in commit 15b188437f9e0192d4ac4472ad66a4e2f62a782f which will be released in version 0.60.8.3.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 06 Oct 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GNU Aspell prezip-bin contains a heap-based buffer overflow vulnerability in the decompressor in prog/prezip.c. The decompressor does not properly check buffer space, so a crafted compressed file can cause out-of-bounds read and write operations on the heap. An attacker who convinces a user to process a malicious compressed file with prezip-bin can trigger memory corruption, leading to a processs crash. This issue was fixed in commit 15b188437f9e0192d4ac4472ad66a4e2f62a782f which will be released in version 0.60.8.3. | |
| Title | Heap Buffer Overflow in GNU Aspell's prezip utility | |
| First Time appeared |
Gnu
Gnu aspell |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:2.3:a:gnu:aspell:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gnu
Gnu aspell |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-10-06T12:50:58.338Z
Reserved: 2026-08-18T10:13:29.246Z
Link: CVE-2026-75818
Updated: 2026-10-06T12:50:43.403Z
Status : Received
Published: 2026-10-06T11:17:29.730
Modified: 2026-10-06T13:16:49.777
Link: CVE-2026-75818
No data.
OpenCVE Enrichment
No data.