[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-0064Date: (C)2011-03-07   (M)2023-12-22


The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1025145
SECUNIA-43559
SECUNIA-43572
SECUNIA-43578
SECUNIA-43800
BID-46632
ADV-2011-0543
ADV-2011-0555
ADV-2011-0558
ADV-2011-0584
ADV-2011-0683
DSA-2178
FEDORA-2011-3194
MDVSA-2011:040
RHSA-2011:0309
SUSE-SR:2011:005
USN-1082-1
http://cgit.freedesktop.org/harfbuzz/commit/?id=a6a79df5fe2ed2cd307e7a991346faee164e70d9
https://bugzilla.mozilla.org/show_bug.cgi?id=606997
https://bugzilla.novell.com/show_bug.cgi?id=672502
https://bugzilla.redhat.com/show_bug.cgi?id=678563
https://build.opensuse.org/request/show/63070
pango-hbbufferensure-bo(65770)

CPE    1
cpe:/a:mozilla:firefox
OVAL    6
oval:org.secpod.oval:def:600192
oval:org.secpod.oval:def:1503288
oval:org.secpod.oval:def:101305
oval:org.secpod.oval:def:300419
...

© SecPod Technologies