Lucene search

K
redhatcveRedhat.comRH:CVE-2024-3859
HistoryApr 18, 2024 - 7:56 a.m.

CVE-2024-3859

2024-04-1807:56:18
redhat.com
access.redhat.com
15
mozilla
opentype
font
vulnerability
cve-2024-3859
integer overflow
out-of-bounds read
security advisory

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.3%

The Mozilla Foundation Security Advisory describes this flaw as: On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font.

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.3%