Impact
T versions 5.5.3 and earlier allows negative code values to bypass length validation. This defect leads to an out‑of‑bounds bit write during decoding, causing wild‑address crashes or allocation failures in the default LSTM engine. The vulnerability is a classic buffer overflow (CWE‑787) and is rated as moderate severity with a CVSS score of 6.9.
Affected Systems
The flaw affects the Tesseract OCR engine, identified by the CNA as tesseract‑ocr:tesseract. All releases up to and including 5.5.3 are susceptible; no fixed release has been released at the time of review.
Risk and Exploitability
An attacker must supply a crafted .traineddata file containing a recoder with negative code values to trigger the defect. The attack vector is local or remote via untrusted OCR data. Because the flaw manifests during data loading, any system that processes external OCR input could be impacted. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate risk that is not currently widely exploited.
OpenCVE Enrichment