CVE-2023-25193
Summary
| CVE | CVE-2023-25193 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-04 20:15:00 UTC |
| Updated | 2023-11-07 04:08:00 UTC |
| Description | hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 36 Update: chromium-110.0.5481.77-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: harfbuzz-7.0.1-2.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| July 2023 Java Platform Standard Edition Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] Fedora 38 Update: harfbuzz-7.0.1-2.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| harfbuzz/hb-ot-layout-gsubgpos.hh at 2822b589bc837fae6f66233e2cf2eef0f6ce8470 · harfbuzz/harfbuzz · GitHub |
MISC |
github.com |
|
| DEPS - chromium/src - Git at Google |
MISC |
chromium.googlesource.com |
|
| [layout] Limit how far we skip when looking back · harfbuzz/harfbuzz@85be877 · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 36 Update: chromium-110.0.5481.77-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160804 Oracle Enterprise Linux Security Update for java-11-openjdk (ELSA-2023-4233)
- 160809 Oracle Enterprise Linux Security Update for java-17-openjdk (ELSA-2023-4159)
- 160812 Oracle Enterprise Linux Security Update for java-11-openjdk (ELSA-2023-4158)
- 160815 Oracle Enterprise Linux Security Update for java-11-openjdk (ELSA-2023-4175)
- 160816 Oracle Enterprise Linux Security Update for java-17-openjdk (ELSA-2023-4177)
- 199629 Ubuntu Security Notification for Open Java Development Toolkit (OpenJDK) Vulnerabilities (USN-6263-1)
- 199638 Ubuntu Security Notification for Open Java Development Toolkit (OpenJDK) 20 Vulnerabilities (USN-6272-1)
- 241837 Red Hat Update for java-17-openjdk (RHSA-2023:4170)
- 241838 Red Hat Update for java-11-openjdk (RHSA-2023:4162)
- 241840 Red Hat Update for java-11-openjdk (RHSA-2023:4165)
- 241841 Red Hat Update for java-11-openjdk (RHSA-2023:4163)
- 241842 Red Hat Update for java-17-openjdk (RHSA-2023:4169)
- 241846 Red Hat Update for java-11-openjdk (RHSA-2023:4164)
- 241847 Red Hat Update for java-17-openjdk (RHSA-2023:4171)
- 241849 Red Hat Update for java-11-openjdk (RHSA-2023:4157)
- 241851 Red Hat Update for java-11-openjdk (RHSA-2023:4175)
- 241854 Red Hat Update for java-17-openjdk (RHSA-2023:4177)
- 241855 Red Hat Update for java-11-openjdk (RHSA-2023:4158)
- 241859 Red Hat Update for java-11-openjdk (RHSA-2023:4233)
- 241860 Red Hat Update for java-17-openjdk (RHSA-2023:4159)
- 257249 CentOS Security Update for java-11-openjdk
- 283700 Fedora Security Update for chromium (FEDORA-2023-4e6353c6f7)
- 284267 Fedora Security Update for cairo (FEDORA-2023-a48406ecd2)
- 354801 Amazon Linux Security Advisory for thunderbird : ALAS2-2023-1983
- 355220 Amazon Linux Security Advisory for harfbuzz : ALAS2023-2023-111
- 355631 Amazon Linux Security Advisory for java-17-amazon-corretto : ALAS2023-2023-258
- 355636 Amazon Linux Security Advisory for java-11-amazon-corretto : ALAS2023-2023-257
- 355651 Amazon Linux Security Advisory for java-11-amazon-corretto : ALAS2-2023-2137
- 355652 Amazon Linux Security Advisory for java-17-amazon-corretto : ALAS2-2023-2138
- 378673 Oracle Java Standard Edition (SE) Critical Patch Update - July 2023 (CPUJUL2023)
- 378691 Amazon Corretto Critical Patch Update (JUL2023)
- 378692 Azul Java Multiple Vulnerabilities Security Update July 2023
- 378761 Alibaba Cloud Linux Security Update for java-11-openjdk (ALINUX2-SA-2023:0035)
- 378792 Red Hat OpenJDK 11.0.20 Security Update for Windows Builds (RHSA-2023:4161)
- 378793 Red Hat OpenJDK 17.0.8 Security Update for Windows Builds (RHSA-2023:4211)
- 378921 Alibaba Cloud Linux Security Update for java-17-openjdk (ALINUX3-SA-2023:0119)
- 378923 Alibaba Cloud Linux Security Update for java-11-openjdk (ALINUX3-SA-2023:0118)
- 503425 Alpine Linux Security Update for openjdk11
- 503427 Alpine Linux Security Update for openjdk17
- 506135 Alpine Linux Security Update for openjdk11
- 506137 Alpine Linux Security Update for openjdk17
- 672975 EulerOS Security Update for harfbuzz (EulerOS-SA-2023-1871)
- 672976 EulerOS Security Update for harfbuzz (EulerOS-SA-2023-1846)
- 673028 EulerOS Security Update for harfbuzz (EulerOS-SA-2023-1977)
- 673049 EulerOS Security Update for harfbuzz (EulerOS-SA-2023-1955)
- 673124 EulerOS Security Update for harfbuzz (EulerOS-SA-2023-2270)
- 673166 EulerOS Security Update for harfbuzz (EulerOS-SA-2023-2294)
- 673350 EulerOS Security Update for harfbuzz (EulerOS-SA-2024-1142)
- 674098 EulerOS Security Update for harfbuzz (EulerOS-SA-2023-3129)
- 754001 SUSE Enterprise Linux Security Update for harfbuzz (SUSE-SU-2023:1822-1)
- 754002 SUSE Enterprise Linux Security Update for harfbuzz (SUSE-SU-2023:1821-1)
- 754003 SUSE Enterprise Linux Security Update for harfbuzz (SUSE-SU-2023:1820-1)
- 754217 SUSE Enterprise Linux Security Update for java-11-openjdk (SUSE-SU-2023:2990-1)
- 754271 SUSE Enterprise Linux Security Update for java-11-openjdk (SUSE-SU-2023:3287-1)
- 905389 Common Base Linux Mariner (CBL-Mariner) Security Update for qt5-qtbase (13224)
- 905398 Common Base Linux Mariner (CBL-Mariner) Security Update for qt5-qtbase (13231)
- 905443 Common Base Linux Mariner (CBL-Mariner) Security Update for harfbuzz (13303)
- 905449 Common Base Linux Mariner (CBL-Mariner) Security Update for mozjs60 (13322)
- 905453 Common Base Linux Mariner (CBL-Mariner) Security Update for harfbuzz (13321)
- 906534 Common Base Linux Mariner (CBL-Mariner) Security Update for harfbuzz (13303-1)
- 906552 Common Base Linux Mariner (CBL-Mariner) Security Update for harfbuzz (13321-1)
- 906606 Common Base Linux Mariner (CBL-Mariner) Security Update for harfbuzz (13321-3)
- 906657 Common Base Linux Mariner (CBL-Mariner) Security Update for harfbuzz (13303-3)
- 906783 Common Base Linux Mariner (CBL-Mariner) Security Update for harfbuzz (13321-5)
- 941188 AlmaLinux Security Update for java-11-openjdk (ALSA-2023:4175)
- 941189 AlmaLinux Security Update for java-17-openjdk (ALSA-2023:4159)
- 941191 AlmaLinux Security Update for java-17-openjdk (ALSA-2023:4177)
- 941192 AlmaLinux Security Update for java-11-openjdk (ALSA-2023:4158)