First published: Fri Dec 31 2021(Updated: )
HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Harfbuzz Project Harfbuzz | =2.9.0 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
=2.9.0 | ||
=34 | ||
=35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-45931 is medium with a CVSS score of 6.5.
HarfBuzz version 2.9.0 is affected by CVE-2021-45931.
Update HarfBuzz to a version that includes the fix for CVE-2021-45931.
You can find more information about CVE-2021-45931 at the following references: [link1], [link2], [link3].
The CWE ID for CVE-2021-45931 is CWE-787.