{"id":"CVE-2026-75818","summary":"Heap Buffer Overflow in GNU Aspell's prezip utility","details":"GNU Aspell prezip-bin contains a heap-based buffer overflow vulnerability in the decompressor in prog/prezip.c. The decompressor does not properly check buffer space, so a crafted compressed file can cause out-of-bounds read and write operations on the heap. An attacker who convinces a user to process a malicious compressed file with prezip-bin can trigger memory corruption, leading to a processs crash.\n\n\n\nThis issue was fixed in commit 15b188437f9e0192d4ac4472ad66a4e2f62a782f which will be released in version 0.60.8.3.","modified":"2026-10-07T02:47:33.820008030Z","published":"2026-10-06T10:57:52.690Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75818.json","unresolved_ranges":[{"extracted_events":[{"fixed":"0.60.8.3"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"CERT-PL","cwe_ids":["CWE-122"]},"references":[{"type":"WEB","url":"http://aspell.net/"},{"type":"ADVISORY","url":"https://cert.pl/en/posts/2026/10/CVE-2026-75818"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75818.json"},{"type":"PACKAGE","url":"https://github.com/GNUAspell/aspell"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75818"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnuaspell/aspell","events":[{"introduced":"0"},{"last_affected":"3de79d40aee4e9ccdc0d83856637949801a3d33b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.60.8.2"}],"source":"CPE_FIELD"}}],"versions":["rel-0.60.8.2","rel-0.60.6.1","rel-0.60.7-20110707"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75818.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N"}]}