CVE-2026-75818
Received Received - Intake

Heap-based Buffer Overflow in GNU Aspell prezip-bin

Vulnerability report for CVE-2026-75818, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: CERT.PL

Description

GNU Aspell prezip-bin contains a heap-based buffer overflow vulnerability in the decompressor in prog/prezip.c. The decompressor does not properly check buffer space, so a crafted compressed file can cause out-of-bounds read and write operations on the heap. An attacker who convinces a user to process a malicious compressed file with prezip-bin can trigger memory corruption, leading to a processs crash. This issue was fixed in commitΒ 15b188437f9e0192d4ac4472ad66a4e2f62a782f which will beΒ released in versionΒ 0.60.8.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
GNU Aspell 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

GNU Aspell prezip-bin has a heap-based buffer overflow in its decompressor. The issue occurs when processing crafted compressed files, causing out-of-bounds memory reads and writes. This can lead to memory corruption and crashes.

Detection Guidance

Detecting this vulnerability requires checking for the presence of vulnerable versions of GNU Aspell prezip-bin. Inspect installed versions with commands like 'aspell --version' or 'prezip-bin --version'. Look for versions prior to 0.60.8.3. Additionally, monitor for crashes when processing compressed files.

Impact Analysis

If you process a malicious compressed file with prezip-bin, an attacker could trigger memory corruption. This may cause the application to crash or potentially allow arbitrary code execution.

Mitigation Strategies

Immediately update GNU Aspell to version 0.60.8.3 or later. If updating is not possible, avoid processing untrusted compressed files with prezip-bin. Restrict user permissions to limit exposure to malicious files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75818. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart