CVE-2015-9274: Medium severity harfbuzz icus for ubuntu vulnerability
Published Nov 15, 2018
·Updated
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layout-gsubgpos-private.hh.
Affected Software
1 affected component
Harfbuzz Project Harfbuzz<1.0.4
Remediation
Event History
Nov 15, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2015-9274.
2
What is the severity of CVE-2015-9274?
The severity of CVE-2015-9274 is medium with a CVSS score of 6.5.
3
How does CVE-2015-9274 cause a denial of service?
CVE-2015-9274 allows remote attackers to cause a denial of service by triggering an invalid read of two bytes, leading to an application crash.
4
Which software versions are affected by CVE-2015-9274?
HarfBuzz versions up to but not including 1.0.4 are affected by CVE-2015-9274.
5
How can I fix CVE-2015-9274?
To fix CVE-2015-9274, update HarfBuzz to version 1.0.4 or above.