Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-25193

Опубликовано: 04 фев. 2023
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 7.5

Описание

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

8.3.0-2build2
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

needs-triage

esm-infra/focal

not-affected

2.6.4-1ubuntu4.3
esm-infra/xenial

not-affected

code not present
focal

released

2.6.4-1ubuntu4.3
jammy

released

2.7.4-1ubuntu3.2
kinetic

ignored

end of life, was needed
lunar

ignored

end of life, was needed

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps/focal

ignored

superseded by openjdk-17
focal

ignored

end of standard support, was ignored [superseded by openjdk-17]
jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps/focal

ignored

superseded by openjdk-17
focal

ignored

end of standard support, was ignored [superseded by openjdk-17]
jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

17.0.8+7-1
esm-apps/bionic

released

17.0.8+7-1~18.04
esm-apps/jammy

released

17.0.8+7-1~22.04
esm-infra/focal

DNE

focal was released [17.0.8+7-1~20.04.2]
focal

released

17.0.8+7-1~20.04.2
jammy

released

17.0.8+7-1~22.04
lunar

released

17.0.8+7-1~23.04
mantic

not-affected

17.0.8+7-1
noble

not-affected

17.0.8+7-1

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps/jammy

ignored

superseded by openjdk-19
esm-infra/focal

DNE

focal

DNE

jammy

ignored

superseded by openjdk-19
lunar

ignored

superseded by openjdk-19
mantic

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

ignored

no longer supported by upstream
lunar

ignored

superseded by openjdk-20
mantic

ignored

end of life, was ignored [superseded by openjdk-20]
noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

lunar

released

20.0.2+9+ds1-0ubuntu1~23.04
mantic

not-affected

20.0.2+9-1
noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

21+35-1
esm-infra/focal

DNE

focal was released [21.0.1+12-2~20.04]
focal

released

21.0.1+12-2~20.04
jammy

released

21.0.1+12-2~22.04
lunar

released

21.0.1+12-2~23.04
mantic

not-affected

21+35-1
noble

not-affected

21+35-1
oracular

not-affected

21+35-1
plucky

not-affected

21+35-1

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

lunar

DNE

mantic

not-affected

oracular

needs-triage

plucky

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
esm-infra/xenial

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
lunar

not-affected

code not present

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps/xenial

ignored

no longer supported by upstream
esm-infra/focal

DNE

focal

DNE

jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

released

11.0.20+8-1ubuntu1
esm-apps/noble

released

11.0.20+8-1ubuntu1
esm-infra/bionic

released

11.0.20+8-1ubuntu1~18.04
esm-infra/focal

not-affected

11.0.20+8-1ubuntu1~20.04
focal

released

11.0.20+8-1ubuntu1~20.04
jammy

released

11.0.20+8-1ubuntu1~22.04
lunar

released

11.0.20+8-1ubuntu1~23.04
mantic

released

11.0.20+8-1ubuntu1
noble

released

11.0.20+8-1ubuntu1

Показывать по

EPSS

Процентиль: 17%
0.00055
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 2 лет назад

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

CVSS3: 7.5
nvd
больше 2 лет назад

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

CVSS3: 7.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 2 лет назад

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to ...

suse-cvrf
около 2 лет назад

Security update for harfbuzz

EPSS

Процентиль: 17%
0.00055
Низкий

7.5 High

CVSS3