USN-7214-1: HarfBuzz vulnerability
Published Jan 16, 2025
·Updated
It was discovered that HarfBuzz incorrecty handled certain memory operations. A remote attacker could use this issue to cause HarfBuzz to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/libharfbuzz-cairo0<9.0.0-1ubuntu0.1
9.0.0-1ubuntu0.1
Ubuntu Ubuntu=24.10
All of the following
ubuntu/libharfbuzz0b<9.0.0-1ubuntu0.1
9.0.0-1ubuntu0.1
Ubuntu Ubuntu=24.10
Event History
Jan 16, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7214-1?
The severity of USN-7214-1 is high as it could lead to denial of service or arbitrary code execution.
2
How do I fix USN-7214-1?
To fix USN-7214-1, update the affected packages to version 9.0.0-1ubuntu0.1 or later.
3
Which versions of Ubuntu are affected by USN-7214-1?
USN-7214-1 affects Ubuntu 24.10 for the libharfbuzz-cairo0 and libharfbuzz0b packages.
4
Can USN-7214-1 lead to remote exploitation?
Yes, a remote attacker could exploit USN-7214-1 to crash HarfBuzz or potentially execute arbitrary code.
5
What should I do if I cannot update to fix USN-7214-1?
If you cannot update, consider isolating affected systems from untrusted networks to mitigate potential risks.