CVE-2023-25193

EUVD-2023-29157
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
harfbuzz_projectharfbuzz
𝑥
≤ 6.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
harfbuzz
bookworm
no-dsa
bullseye
no-dsa
buster
no-dsa
sid
10.1.0-2
fixed
trixie
10.1.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
harfbuzz
bionic
needs-triage
focal
needed
jammy
needed
kinetic
ignored
lunar
ignored
mantic
ignored
noble
not-affected
oracular
not-affected
trusty
not-affected
xenial
not-affected
openjdk
bionic
ignored
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
ignored
openjdk-13
bionic
dne
focal
ignored
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
dne
openjdk-16
bionic
dne
focal
ignored
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
dne
openjdk-17
bionic
Fixed 17.0.8+7-1~18.04
released
focal
Fixed 17.0.8+7-1~20.04.2
released
jammy
Fixed 17.0.8+7-1~22.04
released
lunar
Fixed 17.0.8+7-1~23.04
released
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
openjdk-18
bionic
dne
focal
dne
jammy
ignored
lunar
ignored
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
dne
openjdk-19
bionic
dne
focal
dne
jammy
ignored
lunar
ignored
mantic
ignored
noble
dne
oracular
dne
trusty
dne
xenial
dne
openjdk-20
bionic
dne
focal
dne
jammy
dne
lunar
Fixed 20.0.2+9+ds1-0ubuntu1~23.04
released
mantic
not-affected
noble
dne
oracular
dne
trusty
dne
xenial
dne
openjdk-21
bionic
dne
focal
Fixed 21.0.1+12-2~20.04
released
jammy
Fixed 21.0.1+12-2~22.04
released
lunar
Fixed 21.0.1+12-2~23.04
released
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
dne
openjdk-22
bionic
dne
focal
dne
jammy
dne
lunar
dne
mantic
not-affected
oracular
needs-triage
trusty
dne
xenial
dne
openjdk-8
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
dne
xenial
not-affected
openjdk-9
bionic
dne
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
ignored
openjdk-lts
bionic
Fixed 11.0.20+8-1ubuntu1~18.04
released
focal
Fixed 11.0.20+8-1ubuntu1~20.04
released
jammy
Fixed 11.0.20+8-1ubuntu1~22.04
released
lunar
Fixed 11.0.20+8-1ubuntu1~23.04
released
mantic
Fixed 11.0.20+8-1ubuntu1
released
noble
Fixed 11.0.20+8-1ubuntu1
released
oracular
Fixed 11.0.20+8-1ubuntu1
released
trusty
dne
xenial
dne