CVE-2023-25193: High severity harfbuzz vulnerability
A vulnerability was found HarfBuzz. This flaw allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
Other sources
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this flaw in HarfBuzz?
The vulnerability ID is CVE-2023-25193.
What is the severity of CVE-2023-25193?
The severity of CVE-2023-25193 is high.
How does CVE-2023-25193 affect HarfBuzz?
CVE-2023-25193 allows attackers to trigger O(n^2) growth in HarfBuzz through consecutive marks during the process of looking back for base glyphs when attaching marks.
Which software versions are affected by CVE-2023-25193?
The affected software versions include HarfBuzz 2.3.1-1 up to and inclusive of 6.0.0+dfsg-3.
Are there any remediation steps or fixes available for CVE-2023-25193?
Yes, there are remediation steps available. Please refer to the official references for more information.