Executive brief
Open Chinese Convert is a library used to convert text between Traditional and Simplified Chinese characters. A memory safety vulnerability in the text processing logic allows crafted UTF-8 input to cause a heap buffer overflow. While the reported impact is local execution only, this could affect applications that process untrusted Chinese text, leading to application crashes or potential exploitation in certain contexts.
Technical details
The vulnerability is a heap-based out-of-bounds write (CWE-787) in the MaxMatchSegmentation::Segment function (src/MaxMatchSegmentation.cpp, line 34). The root cause is improper boundary checking when processing truncated UTF-8 sequences. The NextCharLength() function could return a value larger than the remaining input size, causing integer underflow when subtracted from a size_t length counter, leading to out-of-bounds reads/writes. The vulnerability affects OpenCC up to version 1.1.9 and requires local code execution to trigger. A patch (commit 345c9a50ab07018f1b4439776bad78a0d40778ec) released in version 1.2.0 fixes the issue by explicitly tracking buffer boundaries and clamping matched lengths to remaining buffer size. Proof-of-concept code is publicly available.
Affected products
- BYVoid OpenCC up to 1.1.9
Timeline
- 2025-12-23: disclosed: Vulnerability reported in GitHub issue #997
- 2026-01-13: patched: Fix merged in pull request #1005
- 2026-01-18: advisory: Public advisory published as CVE-2025-15536 / GHSA-5pr6-crvp-2j9f