hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
References
Configurations
History
21 Nov 2024, 07:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://chromium.googlesource.com/chromium/src/+/e1f324aa681af54101c1f2d173d92adb80e37088/DEPS#361 - Patch, Third Party Advisory | |
References | () https://github.com/harfbuzz/harfbuzz/blob/2822b589bc837fae6f66233e2cf2eef0f6ce8470/src/hb-ot-layout-gsubgpos.hh - Third Party Advisory | |
References | () https://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dc - Patch, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KWCHWSICWVZSAXP2YAXM65JC2GR53547/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZ5M2GSAIHFPLHYJXUPQ2QDJCLWXUGO3/ - | |
References | () https://security.netapp.com/advisory/ntap-20230725-0006/ - |
07 Nov 2023, 04:08
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
25 Jul 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2023-02-04 20:15
Updated : 2024-11-21 07:49
NVD link : CVE-2023-25193
Mitre link : CVE-2023-25193
CVE.ORG link : CVE-2023-25193
JSON object : View
Products Affected
fedoraproject
- fedora
harfbuzz_project
- harfbuzz
CWE
CWE-770
Allocation of Resources Without Limits or Throttling