Hi,

On Sun, Feb 05, 2023 at 05:30:39PM +0100, Salvatore Bonaccorso wrote:
> Source: harfbuzz
> Version: 6.0.0+dfsg-3
> Severity: important
> Tags: security upstream
> X-Debbugs-Cc: [email protected], Debian Security Team 
> <[email protected]>
> 
> Hi,
> 
> The following vulnerability was published for harfbuzz.
> 
> CVE-2023-25193[0]:
> | hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to
> | trigger O(n^2) growth via consecutive marks during the process of
> | looking back for base glyphs when attaching marks.
> 
> 
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
> 
> For further information see:
> 
> [0] https://security-tracker.debian.org/tracker/CVE-2023-25193
>     https://www.cve.org/CVERecord?id=CVE-2023-25193
> [1] 
> https://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dc

The [1] commit has later on been reverted again, and replaced by
https://github.com/harfbuzz/harfbuzz/commit/8708b9e081192786c027bb7f5f23d76dbe5c19e8
. See 
https://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dc#commitcomment-101335712

Regards,
Salvatore

Reply via email to