CVE-2010-3444

Buffer overflow in the log2vis_utf8 function in pyfribidi.c in GNU FriBidi 0.19.1, 0.19.2, and possibly other versions, as used in PyFriBidi 0.10.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Arabic UTF-8 string that causes original 2-byte UTF-8 sequences to be transformed into 3-byte sequences.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
fribidignu_fribidi
0.19.1
fribidignu_fribidi
0.19.2
kobi_zamirpyfribidi
0.10.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pyfribidi
bullseye
0.12.0+repack-7
fixed
lenny
not-affected
bookworm
0.12.0+repack-9
fixed
sid
0.12.0+repack-10
fixed
trixie
0.12.0+repack-10
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pyfribidi
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
hardy
ignored
dapper
ignored