Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-25193

Published: September 8, 2023Last modified: September 8, 2023

Description

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSopenjdk11Not affected (11.0.20.1_p1-r0)
openjdk11-container-jreNot affected (11.0.20.1_p1-r0)
openjdk11-jvmciNot affected (11.0.20.1_p1-r0)
openjdk11-liteNot affected (11.0.20.1_p1-r0)
openjdk17Not affected (17.0.8.1_p1-r0)
openjdk17-container-jreNot affected (17.0.8.1_p1-r0)
openjdk17-liteNot affected (17.0.8.1_p1-r0)
Streamopenjdk11Not affected (11.0.20.1_p1-r1)
openjdk11-container-jreNot affected (11.0.20.1_p1-r0)
openjdk11-jvmciNot affected (11.0.20.1_p1-r1)
openjdk11-liteNot affected (11.0.20.1_p1-r1)
openjdk17Not affected (17.0.8.1_p1-r1)
openjdk17-container-jreNot affected (17.0.8.1_p1-r0)
openjdk17-liteNot affected (17.0.8.1_p1-r1)

References

ON THIS PAGE