Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-3193

Опубликовано: 19 июл. 2011
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4freetypeNot affected
Red Hat Enterprise Linux 4pangoNot affected
Red Hat Enterprise Linux 4qtNot affected
Red Hat Enterprise Linux 5freetypeNot affected
Red Hat Enterprise Linux 5qtNot affected
Red Hat Enterprise Linux 6freetypeNot affected
Red Hat Enterprise Linux 6pangoNot affected
Red Hat Enterprise Linux 6qt3Not affected
Red Hat Enterprise Linux 4evolution28-pangoFixedRHSA-2011:132521.09.2011
Red Hat Enterprise Linux 4fryskFixedRHSA-2011:132721.09.2011

Показывать по

Дополнительная информация

Статус:

Moderate

EPSS

Процентиль: 88%
0.04038
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.

nvd
около 13 лет назад

Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.

debian
около 13 лет назад

Heap-based buffer overflow in the Lookup_MarkMarkPos function in the H ...

github
около 3 лет назад

Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.

oracle-oval
почти 14 лет назад

ELSA-2011-1326: pango security update (MODERATE)

EPSS

Процентиль: 88%
0.04038
Низкий

5.1 Medium

CVSS2