VDB
Sign up
MEDIUM5.5

GHSA-9qh2-6fxg-9m4g

Open Chinese Convert subject to Denial of Service via Out-of-bounds Read

Quick fix

GHSA-9qh2-6fxg-9m4g — opencc: upgrade to the fixed version with the command below.

npm install opencc@1.1.2

Details

Open Chinese Convert (OpenCC) 1.0.5 allows attackers to cause a denial of service (segmentation fault) because BinaryDict::NewFromFile in BinaryDict.cpp may have out-of-bounds keyOffset and valueOffset values via a crafted .ocd file.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/opencc
Introduced in: 0Fixed in: 1.1.2
Fixnpm install opencc@1.1.2

References