Lucene search

K
gentooGentoo FoundationGLSA-202407-24
HistoryJul 10, 2024 - 12:00 a.m.

HarfBuzz: Denial of Service

2024-07-1000:00:00
Gentoo Foundation
security.gentoo.org
5
harfbuzz
opentype
vulnerabilities
text shaping.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

Low

EPSS

0.002

Percentile

60.8%

Background

HarfBuzz is an OpenType text shaping engine.

Description

Multiple vulnerabilities have been discovered in HarfBuzz. Please review the CVE identifiers referenced below for details.

Impact

hb-ot-layout-gsubgpos.hh in HarfBuzz allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

Workaround

There is no known workaround at this time.

Resolution

All HarfBuzz users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=media-libs/harfbuzz-7.1.0"
OSVersionArchitecturePackageVersionFilename
Gentooanyallmedia-libs/harfbuzz< 7.1.0UNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

Low

EPSS

0.002

Percentile

60.8%