{"id":"SUSE-SU-2024:2632-1","summary":"Security update for espeak-ng","details":"This update for espeak-ng fixes the following issues:\n\n- CVE-2023-49990: Fixed buffer overflow in SetUpPhonemeTable function at synthdata.c (bsc#1218010)\n- CVE-2023-49991: Fixed stack-buffer-underflow exists in the function CountVowelPosition in synthdata.c (bsc#1218006)\n- CVE-2023-49992: Fixed stack-buffer-overflow exists in the function RemoveEnding in dictionary.c (bsc#1218007)\n- CVE-2023-49993: Fixed buffer overflow in ReadClause function at readclause.c (bsc#1218008)\n- CVE-2023-49994: Fixed floating point exception in PeaksToHarmspect at wavegen.c (bsc#1218009)\n","modified":"2026-03-11T07:28:05.713990Z","published":"2024-07-30T07:13:18Z","related":["CVE-2023-49990","CVE-2023-49991","CVE-2023-49992","CVE-2023-49993","CVE-2023-49994"],"upstream":["CVE-2023-49990","CVE-2023-49991","CVE-2023-49992","CVE-2023-49993","CVE-2023-49994"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20242632-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218006"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218007"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218008"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218009"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218010"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-49990"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-49991"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-49992"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-49993"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-49994"}],"affected":[{"package":{"name":"espeak-ng","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP5","purl":"pkg:rpm/suse/espeak-ng&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.50-150300.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"espeak-ng-compat":"1.50-150300.3.3.1","espeak-ng-devel":"1.50-150300.3.3.1","espeak-ng":"1.50-150300.3.3.1","libespeak-ng1":"1.50-150300.3.3.1","espeak-ng-compat-devel":"1.50-150300.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2632-1.json"}},{"package":{"name":"espeak-ng","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP6","purl":"pkg:rpm/suse/espeak-ng&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.50-150300.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"espeak-ng-compat-devel":"1.50-150300.3.3.1","espeak-ng-compat":"1.50-150300.3.3.1","espeak-ng-devel":"1.50-150300.3.3.1","espeak-ng":"1.50-150300.3.3.1","libespeak-ng1":"1.50-150300.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2632-1.json"}},{"package":{"name":"espeak-ng","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/espeak-ng&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.50-150300.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"espeak-ng-compat-devel":"1.50-150300.3.3.1","espeak-ng-compat":"1.50-150300.3.3.1","espeak-ng-devel":"1.50-150300.3.3.1","espeak-ng":"1.50-150300.3.3.1","libespeak-ng1":"1.50-150300.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2632-1.json"}},{"package":{"name":"espeak-ng","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/espeak-ng&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.50-150300.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"espeak-ng-compat-devel":"1.50-150300.3.3.1","espeak-ng-compat":"1.50-150300.3.3.1","espeak-ng-devel":"1.50-150300.3.3.1","espeak-ng":"1.50-150300.3.3.1","libespeak-ng1":"1.50-150300.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:2632-1.json"}}],"schema_version":"1.7.5"}