Description
A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks.
Recommendation
Update the opencc package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.1.9
- Patched version(s): 1.2.0
References
Could your website be exposed too?
SmartScanner can check your website for Open Chinese Convert has Out-of-bounds Write and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Open Chinese Convert subject to Denial of Service via Out-of-bounds Read - CVE-2018-16982
- parse-duration has a Regex Denial of Service that results in event loop delay and out of memory - CVE-2025-25283
- OpenCC has an Out-of-bounds read when processing truncated UTF-8 input - Vulnerability
- lobe-chat has an Open Redirect - CVE-2025-59426


