CVE-2015-9274
published 2018-11-15CVE-2015-9274: HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table…
PriorityP422medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
1.54%
72.1th percentile
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layout-gsubgpos-private.hh.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | harfbuzz | < harfbuzz 1.2.6-1 (bookworm) | harfbuzz 1.2.6-1 (bookworm) |
| harfbuzz_project | harfbuzz | < 1.0.4 | 1.0.4 |
| harfbuzz_project | harfbuzz | >= 0 < 1.2.6-1 | 1.2.6-1 |
| harfbuzz_project | harfbuzz | >= 0 < 1.2.6-1 | 1.2.6-1 |
| harfbuzz_project | harfbuzz | >= 0 < 1.2.6-1 | 1.2.6-1 |
| harfbuzz_project | harfbuzz | >= 0 < 1.2.6-1 | 1.2.6-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-95rc-6f28-2jcq: HarfBuzz before 1
ghsa_unreviewed·2022-05-14
CVE-2015-9274 [MEDIUM] CWE-125 GHSA-95rc-6f28-2jcq: HarfBuzz before 1
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layout-gsubgpos-private.hh.
OSV
CVE-2015-9274: HarfBuzz before 1
osv·2018-11-15·CVSS 6.5
CVE-2015-9274 [MEDIUM] CVE-2015-9274: HarfBuzz before 1
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layout-gsubgpos-private.hh.
Ubuntu
HarfBuzz vulnerability
vendor_ubuntu·2022-11-28
CVE-2015-9274 HarfBuzz vulnerability
Title: HarfBuzz vulnerability
Summary: HarfBuzz could be made to crash if it received specially crafted
input.
Behzad Najjarpour Jabbari discovered that HarfBuzz incorrectly handled
certain inputs. A remote attacker could possibly use this issue to cause
a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
harfbuzz: DoS due to GPOS and GSUB table mishandling
vendor_redhat·2015-09-29·CVSS 6.5
CVE-2015-9274 [MEDIUM] CWE-125 harfbuzz: DoS due to GPOS and GSUB table mishandling
harfbuzz: DoS due to GPOS and GSUB table mishandling
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layout-gsubgpos-private.hh.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: libreoffice (Red Hat Enterprise Linux 6) - Will not fix
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: harfbuzz (Red Hat Enterprise Linux 7) - Not affected
Package: harfbuzz (Red Hat Enterprise Linux 8) - Not affected
Package: mingw-harfbuzz (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2015-9274: harfbuzz - HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (inva...
vendor_debian·2015·CVSS 6.5
CVE-2015-9274 [MEDIUM] CVE-2015-9274: harfbuzz - HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (inva...
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layout-gsubgpos-private.hh.
Scope: local
bookworm: resolved (fixed in 1.2.6-1)
bullseye: resolved (fixed in 1.2.6-1)
forky: resolved (fixed in 1.2.6-1)
sid: resolved (fixed in 1.2.6-1)
trixie: resolved (fixed in 1.2.6-1)
No detection rules found.
No public exploits indexed.
2018-11-15
Published