CVE-2024-56732

EUVD-2024-53379
HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 46%
Affected Products (NVD)
VendorProductVersion
harfbuzz_projectharfbuzz
8.5.0 ≤
𝑥
≤ 10.0.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
harfbuzz
bookworm
6.0.0+dfsg-3
not-affected
bullseye
2.7.4-1
not-affected
forky
12.2.0-1
fixed
sid
12.2.0-1
fixed
trixie
10.2.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
harfbuzz
bionic
needs-triage
focal
not-affected
jammy
not-affected
noble
not-affected
oracular
Fixed 9.0.0-1ubuntu0.1
released
plucky
Fixed 10.2.0-1
released
questing
Fixed 10.2.0-1
released
trusty
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
harfbuzz
Amazon Linux 2023
0:7.0.0-2.amzn2023.0.2
fixed
harfbuzz-debuginfo
Amazon Linux 2023
0:7.0.0-2.amzn2023.0.2
fixed
harfbuzz-debugsource
Amazon Linux 2023
0:7.0.0-2.amzn2023.0.2
fixed
harfbuzz-devel
Amazon Linux 2023
0:7.0.0-2.amzn2023.0.2
fixed
harfbuzz-devel-debuginfo
Amazon Linux 2023
0:7.0.0-2.amzn2023.0.2
fixed
harfbuzz-icu
Amazon Linux 2023
0:7.0.0-2.amzn2023.0.2
fixed
harfbuzz-icu-debuginfo
Amazon Linux 2023
0:7.0.0-2.amzn2023.0.2
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
harfbuzz
Azure Linux 3.0
0:8.3.0-3.azl3
fixed
qtbase
Azure Linux 3.0
0:6.6.3-2.azl3
fixed