CVE-2011-3193
16.06.2012, 00:55
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.Enginsight
Vendor | Product | Version |
---|---|---|
gnome | pango | 𝑥 < 1.25.1 |
qt | qt | 𝑥 < 4.7.4 |
canonical | ubuntu_linux | 10.04 |
canonical | ubuntu_linux | 11.04 |
redhat | enterprise_linux_desktop | 4.0 |
redhat | enterprise_linux_desktop | 5.0 |
redhat | enterprise_linux_desktop | 6.0 |
redhat | enterprise_linux_eus | 6.1 |
redhat | enterprise_linux_server | 4.0 |
redhat | enterprise_linux_server | 5.0 |
redhat | enterprise_linux_server | 6.0 |
redhat | enterprise_linux_workstation | 4.0 |
redhat | enterprise_linux_workstation | 5.0 |
redhat | enterprise_linux_workstation | 6.0 |
opensuse | opensuse | 11.3 |
opensuse | opensuse | 11.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References