The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pango1.0 | Jul 30, 2024 | Mar 7, 2011 |
| Gentoo Linux | — | Upgrade x11-libs/pango. | Oct 30, 2017 | Mar 7, 2011 |
| Oracle_linux | — | Upgrade pango-develUpgrade pango | Oct 16, 2024 | Mar 7, 2011 |
| Suse | — | Upgrade pango-modules-32bitUpgrade pangoUpgrade pango-modulesUpgrade pango-toolsUpgrade pango-develUpgrade libpango-1_0-0Upgrade pango-docUpgrade pango-x86Upgrade libpango-1_0-0-32bitUpgrade typelib-1_0-Pango-1_0Upgrade pango-32bitUpgrade pango-devel-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libpango1.0-0Upgrade gir1.0-pango-1.0 | Nov 8, 2024 | Mar 7, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub