CVE-2022-33068: Integer Overflow
Published Jun 22, 2022
·Updated
An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Affected Software
3 affected components
Harfbuzz Project Harfbuzz=4.3.0
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Remediation
Patch Available
Event History
Jun 22, 2022
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
Description
Frequently Asked Questions
1
What is CVE-2022-33068?
CVE-2022-33068 is an integer overflow vulnerability in the Harfbuzz component hb-ot-shape-fallback.cc, allowing attackers to cause a Denial of Service (DoS) attack.
2
What is the severity of CVE-2022-33068?
The severity of CVE-2022-33068 is medium with a CVSS score of 5.5.
3
How can attackers exploit CVE-2022-33068?
Attackers can exploit CVE-2022-33068 by performing unspecified vectors to trigger an integer overflow and cause a Denial of Service (DoS) attack.
4
What software versions are affected by CVE-2022-33068?
The Harfbuzz version 4.3.0 is affected by CVE-2022-33068.
5
How can I fix the CVE-2022-33068 vulnerability?
To fix the CVE-2022-33068 vulnerability, update Harfbuzz to a version that is not affected, such as version 4.3.1 or later.