EUVD Vulnerability Catalog
EUVD-2026-93366
Severity: LOW
Base Score: 1.8
CVSS Version: 4.0
Vulnerability Description
GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service.
This issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N
▪
Attack Vector (AV): Local
▪
Attack Complexity (AC): High
▪
Attack Requirements (AT): None
▪
Privileges Required (PR): None
▪
User Interaction (UI): Active
▪
Vulnerability Confidentiality Impact (VC): None
▪
Vulnerability Integrity Impact (VI): None
▪
Vulnerability Availability Impact (VA): Low
▪
Subsequent Confidentiality Impact (SC): None
▪
Subsequent Integrity Impact (SI): Low
▪
Subsequent Availability Impact (SA): None
Affected Vendors & Systems
Vendor
GNU
References & Advisory Links
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
CERT-PL
EPSS Probability
0
Known Aliases
CVE-2026-75820
Published On
2026-10-06
Last Updated
2026-10-06