CVE-2023-49990 describes a buffer overflow vulnerability in Espeak-ng version 1.52-dev, specifically within the SetUpPhonemeTable function in synthdata.c. This medium-severity vulnerability (CVSS 5.3) requires local access and user interaction, potentially leading to limited impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.52CPE matchmatch criteria | cpe:2.3:a:espeak-ng:espeak-ng:1.52:dev:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-49990
Jun 11, 2024Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.
Dec 12, 2023espeak-ng: buffer overflow in SetUpPhonemeTable function at synthdata.c
Dec 12, 2023