Описание
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 4 | freetype | Not affected | ||
Red Hat Enterprise Linux 4 | pango | Not affected | ||
Red Hat Enterprise Linux 4 | qt | Not affected | ||
Red Hat Enterprise Linux 5 | freetype | Not affected | ||
Red Hat Enterprise Linux 5 | qt | Not affected | ||
Red Hat Enterprise Linux 6 | freetype | Not affected | ||
Red Hat Enterprise Linux 6 | pango | Not affected | ||
Red Hat Enterprise Linux 6 | qt3 | Not affected | ||
Red Hat Enterprise Linux 4 | evolution28-pango | Fixed | RHSA-2011:1325 | 21.09.2011 |
Red Hat Enterprise Linux 4 | frysk | Fixed | RHSA-2011:1327 | 21.09.2011 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.1 Medium
CVSS2
Связанные уязвимости
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the H ...
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
EPSS
5.1 Medium
CVSS2