Description
A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. Patch name: 345c9a50ab07018f1b4439776bad78a0d40778ec. To fix this issue, it is recommended to deploy a patch.
Problem types
Product status
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
Timeline
| 2026-01-17: | Advisory disclosed |
| 2026-01-17: | VulDB entry created |
| 2026-02-07: | VulDB entry last update |
Credits
Oneafter (VulDB User)
References
github.com/BYVoid/OpenCC/issues/997
vuldb.com/?id.341708 (VDB-341708 | BYVoid OpenCC MaxMatchSegmentation.cpp MaxMatchSegmentation heap-based overflow)
vuldb.com/?ctiid.341708 (VDB-341708 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.733347 (Submit #733347 | BYVoid OpenCC ver.1.1.9 and master-branch Heap-based Buffer Overflow)
github.com/BYVoid/OpenCC/issues/997
github.com/BYVoid/OpenCC/pull/1005
github.com/oneafter/1222/blob/main/repro
github.com/...ommit/345c9a50ab07018f1b4439776bad78a0d40778ec
github.com/BYVoid/OpenCC/