Open Chinese Convert (OpenCC) 1.0.5 allows attackers to cause a denial of service (segmentation fault) because BinaryDict::NewFromFile in BinaryDict.cpp may have out-of-bounds keyOffset and valueOffset values via a crafted .ocd file. Upstream issue: https://github.com/BYVoid/OpenCC/issues/303
In version 0.4.3, the code is quite different. The PoCs can still crash the opencc_dict binary, but it's at a different location and does not seem to pose a security risk.
Statement: This issue did not affect the versions of opencc as shipped with Red Hat Enterprise Linux 7.