CVE-2022-33068Integer Overflow or Wraparound in Harfbuzz

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 65.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 23
Latest updateJul 19

Description

An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

debiandebian/harfbuzz< harfbuzz 5.2.0-2 (bookworm)
Debianharfbuzz_project/harfbuzz< 5.2.0-2+2

Also affects: Fedora 35, 36

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cq67-chj5-8385: An integer overflow in the component hb-ot-shape-fallback2022-06-24
OSV
CVE-2022-33068: An integer overflow in the component hb-ot-shape-fallback2022-06-23

📋Vendor Advisories

4
Ubuntu
HarfBuzz vulnerability2022-07-19
Red Hat
harfbuzz: integer overflow in the component hb-ot-shape-fallback.cc2022-06-23
Microsoft
An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.2022-06-14
Debian
CVE-2022-33068: harfbuzz - An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 ...2022
CVE-2022-33068 — Integer Overflow or Wraparound | cvebase