CVE-2019-17544: Canonical Ubuntu Linux
Critical severity, CVSS 9.1. EPSS: 3.3% chance of exploitation in the next 30 days.
libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only
- GNU Aspell: before 0.60.8 (fixed in 0.60.8)
Published 2019-10-14. Last modified 2026-06-17.