CVE-2023-25193
published 2023-02-04CVE-2023-25193: hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.81%
76.2th percentile
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | harfbuzz | < harfbuzz 8.0.0-1 (forky) | harfbuzz 8.0.0-1 (forky) |
| fedoraproject | fedora | — | — |
| harfbuzz_project | harfbuzz | <= 6.0.0 | — |
| harfbuzz_project | harfbuzz | >= 0 < 8.0.0-1 | 8.0.0-1 |
| harfbuzz_project | harfbuzz | >= 0 < 8.0.0-1 | 8.0.0-1 |
| msrc | azl3_mozjs_102.15.1-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_harfbuzz_3.4.0-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_qt5-qtbase_5.12.11-15_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_harfbuzz_3.4.0-1_on_cbl_mariner_1.0 | — | — |
| msrc | cm1_mozjs60_60.9.0-13_on_cbl_mariner_1.0 | — | — |
| msrc | cm1_qt5-qtbase_5.12.11-7_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_oracle3.7HIGH
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
HarfBuzz vulnerability
vendor_ubuntu·2025-02-03
CVE-2023-25193 HarfBuzz vulnerability
Title: HarfBuzz vulnerability
Summary: HarfBuzz could be made to consume resources if it opened a specially
crafted font.
It was discovered that HarfBuzz incorrectly handled shaping certain fonts.
A remote attacker could possibly use this issue to cause HarfBuzz to
consume resources, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
OpenJDK regression
vendor_ubuntu·2023-08-30·CVSS 3.1
[LOW] OpenJDK regression
Title: OpenJDK regression
Summary: USN-6263-1 introduced a regression in OpenJDK 11 and OpenJDK 17.
USN-6263-1 fixed vulnerabilities in OpenJDK. Unfortunately, that update
introduced a regression when opening APK, ZIP or JAR files in OpenJDK 11
and OpenJDK 17. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Motoyasu Saburi discovered that OpenJDK incorrectly handled special
characters in file name parameters. An attacker could possibly use
this issue to insert, edit or obtain sensitive information. This issue
only affected OpenJDK 11 and OpenJDK 17. (CVE-2023-22006)
Eirik Bjørsnøs discovered that OpenJDK incorrectly handled certain ZIP
archives. An attacker could possibly use this issue to cause a denial
of service. This issue only affect
Ubuntu
OpenJDK 20 vulnerabilities
vendor_ubuntu·2023-08-03·CVSS 3.1
CVE-2023-22044 [LOW] OpenJDK 20 vulnerabilities
Title: OpenJDK 20 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 20.
Motoyasu Saburi discovered that OpenJDK 20 incorrectly handled special
characters in file name parameters. An attacker could possibly use
this issue to insert, edit or obtain sensitive information.
(CVE-2023-22006)
Eirik Bjørsnøs discovered that OpenJDK 20 incorrectly handled certain ZIP
archives. An attacker could possibly use this issue to cause a denial
of service. (CVE-2023-22036)
David Stancu discovered that OpenJDK 20 had a flaw in the AES cipher
implementation. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2023-22041)
Zhiqiang Zang discovered that OpenJDK 20 incorrectly handled array accesses
when using the binary '%' operator. An attacker could possibl
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2023-08-01·CVSS 3.1
CVE-2023-22045 [LOW] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
Motoyasu Saburi discovered that OpenJDK incorrectly handled special
characters in file name parameters. An attacker could possibly use
this issue to insert, edit or obtain sensitive information. This issue
only affected OpenJDK 11 and OpenJDK 17. (CVE-2023-22006)
Eirik Bjørsnøs discovered that OpenJDK incorrectly handled certain ZIP
archives. An attacker could possibly use this issue to cause a denial
of service. This issue only affected OpenJDK 11 and OpenJDK 17.
(CVE-2023-22036)
David Stancu discovered that OpenJDK had a flaw in the AES cipher
implementation. An attacker could possibly use this issue to obtain
sensitive information. This issue only affected OpenJDK 11 and OpenJDK 17.
(CVE-2023-2204
Oracle
Oracle Oracle Java SE Risk Matrix: 2D (Harfbuzz) — CVE-2023-25193
vendor_oracle·2023-07-15·CVSS 3.7
CVE-2023-25193 [HIGH] Oracle Oracle Java SE Risk Matrix: 2D (Harfbuzz) — CVE-2023-25193
Oracle Oracle Java SE Risk Matrix: 2D (Harfbuzz) vulnerability
CVE: CVE-2023-25193
CVSS: 3.7
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Microsoft
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
vendor_msrc·2023-02-14·CVSS 7.5
CVE-2023-25193 [HIGH] CWE-770 hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to refle
Red Hat
harfbuzz: allows attackers to trigger O(n^2) growth via consecutive marks
vendor_redhat·2023-02-04·CVSS 7.5
CVE-2023-25193 [HIGH] CWE-770 harfbuzz: allows attackers to trigger O(n^2) growth via consecutive marks
harfbuzz: allows attackers to trigger O(n^2) growth via consecutive marks
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
A vulnerability was found HarfBuzz. This flaw allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
Package: Linux (Red Hat build of OpenJDK 11) - Affected
Package: Windows (Red Hat build of OpenJDK 11) - Affected
Package: Linux (Red Hat build of OpenJDK 17) - Affected
Package: Windows (Red Hat build of OpenJDK 17) - Affected
Package: Linux (Red Hat build of OpenJDK 1.8) - Not affected
Package: Windows (Red Hat build of OpenJDK 1.8) - Not affe
Debian
CVE-2023-25193: harfbuzz - hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O...
vendor_debian·2023·CVSS 7.5
CVE-2023-25193 [HIGH] CVE-2023-25193: harfbuzz - hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O...
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 8.0.0-1)
sid: resolved (fixed in 8.0.0-1)
trixie: resolved (fixed in 8.0.0-1)
OSV
openjdk-lts, openjdk-17 regression
osv·2023-08-30·CVSS 3.1
[LOW] openjdk-lts, openjdk-17 regression
openjdk-lts, openjdk-17 regression
USN-6263-1 fixed vulnerabilities in OpenJDK. Unfortunately, that update
introduced a regression when opening APK, ZIP or JAR files in OpenJDK 11
and OpenJDK 17. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Motoyasu Saburi discovered that OpenJDK incorrectly handled special
characters in file name parameters. An attacker could possibly use
this issue to insert, edit or obtain sensitive information. This issue
only affected OpenJDK 11 and OpenJDK 17. (CVE-2023-22006)
Eirik Bjørsnøs discovered that OpenJDK incorrectly handled certain ZIP
archives. An attacker could possibly use this issue to cause a denial
of service. This issue only affected OpenJDK 11 and OpenJDK 17.
(CVE-2023-22036)
David Stancu disco
OSV
openjdk-8, openjdk-lts, openjdk-17 vulnerabilities
osv·2023-08-01·CVSS 3.1
CVE-2023-22006 [LOW] openjdk-8, openjdk-lts, openjdk-17 vulnerabilities
openjdk-8, openjdk-lts, openjdk-17 vulnerabilities
Motoyasu Saburi discovered that OpenJDK incorrectly handled special
characters in file name parameters. An attacker could possibly use
this issue to insert, edit or obtain sensitive information. This issue
only affected OpenJDK 11 and OpenJDK 17. (CVE-2023-22006)
Eirik Bjørsnøs discovered that OpenJDK incorrectly handled certain ZIP
archives. An attacker could possibly use this issue to cause a denial
of service. This issue only affected OpenJDK 11 and OpenJDK 17.
(CVE-2023-22036)
David Stancu discovered that OpenJDK had a flaw in the AES cipher
implementation. An attacker could possibly use this issue to obtain
sensitive information. This issue only affected OpenJDK 11 and OpenJDK 17.
(CVE-2023-22041)
Zhiqiang Zang discovered that Ope
GHSA
GHSA-v8ff-vmc3-wr4m: hb-ot-layout-gsubgpos
ghsa_unreviewed·2023-02-04
CVE-2023-25193 [HIGH] CWE-770 GHSA-v8ff-vmc3-wr4m: hb-ot-layout-gsubgpos
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
OSV
CVE-2023-25193: hb-ot-layout-gsubgpos
osv·2023-02-04·CVSS 7.5
CVE-2023-25193 [HIGH] CVE-2023-25193: hb-ot-layout-gsubgpos
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://chromium.googlesource.com/chromium/src/+/e1f324aa681af54101c1f2d173d92adb80e37088/DEPS#361https://github.com/harfbuzz/harfbuzz/blob/2822b589bc837fae6f66233e2cf2eef0f6ce8470/src/hb-ot-layout-gsubgpos.hhhttps://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dchttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KWCHWSICWVZSAXP2YAXM65JC2GR53547/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZ5M2GSAIHFPLHYJXUPQ2QDJCLWXUGO3/https://security.netapp.com/advisory/ntap-20230725-0006/https://chromium.googlesource.com/chromium/src/+/e1f324aa681af54101c1f2d173d92adb80e37088/DEPS#361https://github.com/harfbuzz/harfbuzz/blob/2822b589bc837fae6f66233e2cf2eef0f6ce8470/src/hb-ot-layout-gsubgpos.hhhttps://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dchttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KWCHWSICWVZSAXP2YAXM65JC2GR53547/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZ5M2GSAIHFPLHYJXUPQ2QDJCLWXUGO3/https://security.netapp.com/advisory/ntap-20230725-0006/
2023-02-04
Published