CVE-2011-3193: Buffer Overflow
Heap-based buffer overflow in the LookupMarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3193?
CVE-2011-3193 is classified as a high severity vulnerability due to its potential to cause a denial of service and execute arbitrary code.
How do I fix CVE-2011-3193?
To fix CVE-2011-3193, you should update to versions of Qt later than 4.7.4 and Pango later than 1.25.1.
What systems are affected by CVE-2011-3193?
CVE-2011-3193 affects various systems including Qt versions before 4.7.4, Pango versions before 1.25.1, and multiple versions of Red Hat and Ubuntu distributions.
What type of attack can exploit CVE-2011-3193?
CVE-2011-3193 can be exploited through crafted font files, allowing remote attackers to crash the application or potentially execute arbitrary code.
Is there a patch available for CVE-2011-3193?
Yes, patches and updated versions are available for affected software to mitigate the risks posed by CVE-2011-3193.