|
231 | 231 | } |
232 | 232 | ] |
233 | 233 | }, |
234 | | - { |
235 | | - "id": "CVE-2022-33068", |
236 | | - "details": "An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.", |
237 | | - "aliases": [ |
238 | | - "ROOT-OS-DEBIAN-11-CVE-2022-33068", |
239 | | - "ROOT-OS-DEBIAN-bullseye-CVE-2022-33068" |
240 | | - ], |
241 | | - "modified": "<RFC3339 date with the year 2026>", |
242 | | - "published": "2022-06-23T17:15:14.350Z", |
243 | | - "related": [ |
244 | | - "ALSA-2022:8384", |
245 | | - "SUSE-SU-2022:2663-1", |
246 | | - "SUSE-SU-2022:2664-1", |
247 | | - "openSUSE-SU-2022:2663-1", |
248 | | - "openSUSE-SU-2024:12168-1" |
249 | | - ], |
250 | | - "references": [ |
251 | | - { |
252 | | - "type": "WEB", |
253 | | - "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FQBJ24W6TXLSAQWCFW7IBGUMX4AJI3S4/" |
254 | | - }, |
255 | | - { |
256 | | - "type": "WEB", |
257 | | - "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQMEXOVDL3T2UXKBCON7JSOCE646G7HG/" |
258 | | - }, |
259 | | - { |
260 | | - "type": "WEB", |
261 | | - "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W56WTC5IY4EIUHVUIHMCXA3BSBZLSZCI/" |
262 | | - }, |
263 | | - { |
264 | | - "type": "ADVISORY", |
265 | | - "url": "https://github.com/harfbuzz/harfbuzz/commit/62e803b36173fd096d7ad460dd1d1db9be542593" |
266 | | - }, |
267 | | - { |
268 | | - "type": "ADVISORY", |
269 | | - "url": "https://github.com/harfbuzz/harfbuzz/issues/3557" |
270 | | - }, |
271 | | - { |
272 | | - "type": "ADVISORY", |
273 | | - "url": "https://security.gentoo.org/glsa/202209-11" |
274 | | - }, |
275 | | - { |
276 | | - "type": "REPORT", |
277 | | - "url": "https://github.com/harfbuzz/harfbuzz/issues/3557" |
278 | | - }, |
279 | | - { |
280 | | - "type": "FIX", |
281 | | - "url": "https://github.com/harfbuzz/harfbuzz/commit/62e803b36173fd096d7ad460dd1d1db9be542593" |
282 | | - }, |
283 | | - { |
284 | | - "type": "FIX", |
285 | | - "url": "https://github.com/harfbuzz/harfbuzz/issues/3557" |
286 | | - }, |
287 | | - { |
288 | | - "type": "EVIDENCE", |
289 | | - "url": "https://github.com/harfbuzz/harfbuzz/issues/3557" |
290 | | - } |
291 | | - ], |
292 | | - "affected": [ |
293 | | - { |
294 | | - "ranges": [ |
295 | | - { |
296 | | - "type": "GIT", |
297 | | - "repo": "https://github.com/behdad/harfbuzz", |
298 | | - "events": [ |
299 | | - { |
300 | | - "introduced": "0" |
301 | | - } |
302 | | - ] |
303 | | - } |
304 | | - ], |
305 | | - "database_specific": "<Any value>" |
306 | | - }, |
307 | | - { |
308 | | - "ranges": [ |
309 | | - { |
310 | | - "type": "GIT", |
311 | | - "repo": "https://github.com/harfbuzz/harfbuzz", |
312 | | - "events": [ |
313 | | - { |
314 | | - "introduced": "0" |
315 | | - }, |
316 | | - { |
317 | | - "fixed": "62e803b36173fd096d7ad460dd1d1db9be542593" |
318 | | - } |
319 | | - ] |
320 | | - } |
321 | | - ], |
322 | | - "versions": 154, |
323 | | - "database_specific": "<Any value>" |
324 | | - } |
325 | | - ], |
326 | | - "schema_version": "1.7.3", |
327 | | - "severity": [ |
328 | | - { |
329 | | - "type": "CVSS_V3", |
330 | | - "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" |
331 | | - } |
332 | | - ] |
333 | | - }, |
334 | 234 | { |
335 | 235 | "id": "CVE-2023-25193", |
336 | 236 | "details": "hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.", |
|
0 commit comments