UbuntuUpdates.org

Package "espeak-ng"

Name: espeak-ng

Description:

Multi-lingual software speech synthesizer

Latest version: 1.50+dfsg-10ubuntu0.1
Release: jammy (22.04)
Level: updates
Repository: universe
Homepage: https://github.com/espeak-ng/espeak-ng

Links


Download "espeak-ng"


Other versions of "espeak-ng" in Jammy

Repository Area Version
base universe 1.50+dfsg-10
base main 1.50+dfsg-10
security main 1.50+dfsg-10ubuntu0.1
security universe 1.50+dfsg-10ubuntu0.1
updates main 1.50+dfsg-10ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.50+dfsg-10ubuntu0.1 2024-07-01 08:07:14 UTC

  espeak-ng (1.50+dfsg-10ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: buffer overflow (CVE-2023-49990, CVE-2023-49992,
    CVE-2023-49993), buffer underflow (CVE-2023-49991) and floating point
    exception issues (CVE-2023-49994)
    - debian/patches/CVE-2023-49990_49991_49992_49993_49994.patch: Fix
      CVE crashes
    - CVE-2023-49990
    - CVE-2023-49991
    - CVE-2023-49992
    - CVE-2023-49993
    - CVE-2023-49994

 -- Nishit Majithia <email address hidden> Wed, 26 Jun 2024 17:36:08 +0530

CVE-2023-49990 Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.
CVE-2023-49992 Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c.
CVE-2023-49993 Espeak-ng 1.52-dev was discovered to contain a Buffer Overflow via the function ReadClause at readclause.c.
CVE-2023-49991 Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.
CVE-2023-49994 Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.



About   -   Send Feedback to @ubuntu_updates