CVE-2011-0064Pango vulnerability

9 documents8 sources
Severity
6.8MEDIUMNVD
EPSS
3.1%
top 13.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 7
Latest updateMay 3

Description

The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDgnome/pango1.28.3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-49v5-wqh2-vj5q: The hb_buffer_ensure function in hb-buffer2022-05-03
OSV
CVE-2011-0064: The hb_buffer_ensure function in hb-buffer2011-03-07
CVEList
CVE-2011-0064: The hb_buffer_ensure function in hb-buffer2011-03-07

📋Vendor Advisories

3
Ubuntu
Pango vulnerabilities2011-03-02
Red Hat
pango: missing memory reallocation failure checking in hb_buffer_ensure2011-03-01
Debian
CVE-2011-0064: pango1.0 - The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28....2011

💬Community

2
Bugzilla
CVE-2011-0064 pango: missing memory reallocation failure checking in hb_buffer_ensure [fedora-all]2011-03-01
Bugzilla
CVE-2011-0064 pango: missing memory reallocation failure checking in hb_buffer_ensure2011-02-18
CVE-2011-0064 — Gnome Pango vulnerability | cvebase