CVE-2021-45931: Medium severity harfbuzz vulnerability
Published Dec 31, 2021
·Updated
HarfBuzz 2.9.0 has an out-of-bounds write in hbbitsetinvertiblet::set (called from hbsparsesett<hbbitsetinvertiblet>::set and hbsetcopy).
Affected Software
3 affected components
Harfbuzz Project Harfbuzz=2.9.0
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Remediation
Event History
Dec 31, 2021
CVE Published
via MITRE·11:58 PM
Data Sourced
via MITRE·11:58 PM
Description
Jan 1, 2022
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-45931?
The severity of CVE-2021-45931 is medium with a CVSS score of 6.5.
2
Which software versions are affected by CVE-2021-45931?
HarfBuzz version 2.9.0 is affected by CVE-2021-45931.
3
How can I fix CVE-2021-45931?
Update HarfBuzz to a version that includes the fix for CVE-2021-45931.
4
Where can I find more information about CVE-2021-45931?
You can find more information about CVE-2021-45931 at the following references: [link1], [link2], [link3].
5
What is the CWE ID for CVE-2021-45931?
The CWE ID for CVE-2021-45931 is CWE-787.