First published: Wed Jun 22 2022(Updated: )
An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Harfbuzz Project Harfbuzz | =4.3.0 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-33068 is an integer overflow vulnerability in the Harfbuzz component hb-ot-shape-fallback.cc, allowing attackers to cause a Denial of Service (DoS) attack.
The severity of CVE-2022-33068 is medium with a CVSS score of 5.5.
Attackers can exploit CVE-2022-33068 by performing unspecified vectors to trigger an integer overflow and cause a Denial of Service (DoS) attack.
The Harfbuzz version 4.3.0 is affected by CVE-2022-33068.
To fix the CVE-2022-33068 vulnerability, update Harfbuzz to a version that is not affected, such as version 4.3.1 or later.