CVE-2024-56732: HarfBuzz heap-buffer-overflow on hb_cairo_glyphs_from_buffer
HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hbcairoglyphsfrombuffer function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/harfbuzzto a version that resolves this vulnerability.Fixed in 2.7.4-1Fixed in 6.0.0+dfsg-3Fixed in 10.2.0-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56732?
CVE-2024-56732 is classified as a critical vulnerability due to the potential for a heap-based buffer overflow that can lead to arbitrary code execution.
How do I fix CVE-2024-56732?
To mitigate CVE-2024-56732, update HarfBuzz to version 2.7.4-1, 6.0.0+dfsg-3, or 10.2.0-1.
What versions of HarfBuzz are affected by CVE-2024-56732?
HarfBuzz versions 8.5.0 through 10.0.1 are affected by CVE-2024-56732.
Can CVE-2024-56732 lead to system compromise?
Yes, CVE-2024-56732 can potentially allow attackers to execute arbitrary code and compromise the system.
Which function is associated with CVE-2024-56732?
CVE-2024-56732 is associated with the hb_cairo_glyphs_from_buffer function in the HarfBuzz library.