Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-45931

Опубликовано: 01 янв. 2022
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).

An out-of-bounds write flaw was found in HarfBuzz, arising from a boundary error in the hb_bit_set_invertible_t::set() function when processing untrusted input. This flaw allows an attacker to create a specially crafted file, convince the victim to open it, and trigger an out-of-bounds write. In some cases, this issue could lead to the execution of arbitrary code on the target system or, more commonly, result in a denial of service attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 6libreofficeNot affected
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 7harfbuzzNot affected
Red Hat Enterprise Linux 8harfbuzzNot affected
Red Hat Enterprise Linux 8mingw-harfbuzzNot affected
Red Hat Enterprise Linux 9harfbuzzNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2036820harfbuzz: out-of-bounds write in hb_bit_set_invertible_t::set

EPSS

Процентиль: 73%
0.00769
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).

CVSS3: 6.5
nvd
около 4 лет назад

HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).

CVSS3: 6.5
debian
около 4 лет назад

HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t:: ...

CVSS3: 6.5
github
около 4 лет назад

HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).

EPSS

Процентиль: 73%
0.00769
Низкий

6.3 Medium

CVSS3