Search CVE reports


Toggle filters

1 – 10 of 13 results


CVE-2022-38266

Medium priority
Vulnerable

An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.

2 affected packages

tesseract, leptonlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tesseract Not affected Not affected Not affected Vulnerable
leptonlib Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-36281

Medium priority
Vulnerable

Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.

1 affected package

leptonlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
leptonlib Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2020-36280

Medium priority
Vulnerable

Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.

1 affected package

leptonlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
leptonlib Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2020-36279

Medium priority
Vulnerable

Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.

1 affected package

leptonlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
leptonlib Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2020-36278

Medium priority
Vulnerable

Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.

1 affected package

leptonlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
leptonlib Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2020-36277

Medium priority
Vulnerable

Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.

1 affected package

leptonlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
leptonlib Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2018-3836

Medium priority

Some fixes available 2 of 3

An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary code execution. An...

1 affected package

leptonlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
leptonlib Not affected Not affected Not affected
Show less packages

CVE-2018-7442

Medium priority

Some fixes available 15 of 19

An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversal and arbitrary file overwrite.

1 affected package

leptonlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
leptonlib Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2018-7441

Low priority

Some fixes available 15 of 19

Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or have unspecified other impact by creating files in advance or winning a race condition, as demonstrated by...

1 affected package

leptonlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
leptonlib Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2018-7440

Medium priority

Some fixes available 1 of 3

An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot rootname argument. This issue exists because of an incomplete fix for CVE-2018-3836.

1 affected package

leptonlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
leptonlib Not affected Not affected Not affected Fixed
Show less packages