Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
Liblouis is an open source braille translator and back-translator named in
honor of Louis Braille. It features support for computer and literary
braille, supports contracted and uncontracted translation for many
languages and has support for hyphenation. New languages can easily be
added through tables that support a rule or dictionary based approach.
Liblouis also supports math braille (Nemeth and Marburg).
Security Fix(es):
* A missing fix for one stack-based buffer overflow in findTable() for
CVE-2014-8184 was discovered. An attacker could cause denial of service or
potentially allow arbitrary code execution. (CVE-2017-15101)
Red Hat would like to thank Samuel Thibault for reporting this issue.
https://access.redhat.com/security/cve/CVE-2017-15101 https://access.redhat.com/security/updates/classification/#moderate
Red Hat Enterprise Linux Client (v. 7):
Source:
liblouis-2.5.2-12.el7_4.src.rpm
noarch:
liblouis-python-2.5.2-12.el7_4.noarch.rpm
x86_64:
liblouis-2.5.2-12.el7_4.i686.rpm
liblouis-2.5.2-12.el7_4.x86_64.rpm
liblouis-debuginfo-2.5.2-12.el7_4.i686.rpm
liblouis-debuginfo-2.5.2-12.el7_4.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
noarch:
liblouis-doc-2.5.2-12.el7_4.noarch.rpm
x86_64:
liblouis-debuginfo-2.5.2-12.el7_4.i686.rpm
liblouis-debuginfo-2.5.2-12.el7_4.x86_64.rpm
liblouis-devel-2.5.2-12.el7_4.i686.rpm
liblouis-devel-2.5.2-12.el7_4.x86_64.rpm
liblouis-utils-2.5.2-12.el7_4.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
liblouis-2.5.2-12.el7_4.src.rpm
noarch:
liblouis-python-2.5.2-12.el7_4.noarch.rpm
ppc64:
liblouis-2.5.2-12.el7_4.ppc.rpm
liblouis-2.5.2-12.el7_4.ppc64.rpm
liblouis-debuginfo-2.5.2-12.el7_4.ppc.rpm
liblouis-debuginfo-2.5.2-12.el7_4.ppc64.rpm
ppc64le:
liblouis-2.5.2-12.el7_4.ppc64le.rpm
liblouis-debuginfo-2.5.2-12.el7_4.ppc64le.rpm
s390x:
liblouis-2.5.2-12.el7_4.s390.rpm
liblouis-2.5.2-12.el7_4.s390x.rpm
liblouis-debuginfo-2.5.2-12.el7_4.s390.rpm
liblouis-debuginfo-2.5.2-12.el7_4.s390x.rpm
x86_64:
liblouis-2.5.2-12.el7_4.i686.rpm
liblouis-2.5.2-12.el7_4.x86_64.rpm
liblouis-debuginfo-2.5.2-12.el7_4.i686.rpm
Read the Full Advisory
An update for liblouis is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, noarch, ppc64le
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - aarch64, noarch, ppc64le
1511023 - CVE-2017-15101 liblouis: incomplete fix for CVE-2014-8184
Get the latest Linux and open source security news straight to your inbox.