7.5
CVSSv3

CVE-2023-25193

Published: 04/02/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

hb-ot-layout-gsubgpos.hh in HarfBuzz up to and including 6.0.0 allows malicious users to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

harfbuzz project harfbuzz

fedoraproject fedora 36

Vendor Advisories

Debian Bug report logs - #1030612 harfbuzz: CVE-2023-25193 Package: src:harfbuzz; Maintainer for src:harfbuzz is أحمد المحمودي (Ahmed El-Mahmoudy) <aelmahmoudy@userssourceforgenet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 5 Feb 2023 16:33:04 UTC Severity: important Tags: securi ...
Synopsis Moderate: java-11-openjdk security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rate ...
概述 Moderate: Red Hat OpenShift Dev Spaces Security Update 类型/严重性 Security Advisory: Moderate 标题 Red Hat OpenShift Dev Spaces provides a cloud developer workspace server and abrowser-based IDE built for teams and organizations Dev Spaces runs inOpenShift and is well-suited for container-based developmentThe 371 release is ...
Synopsis Moderate: java-17-openjdk security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for java-17-openjdk is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rate ...
概述 Moderate: java-17-openjdk security and bug fix update 类型/严重性 Security Advisory: Moderate Red Hat Insights 补丁分析 识别并修复受此公告影响的系统。 查看受影响的系统 标题 An update for java-17-openjdk is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this up ...
Synopsis Moderate: OpenJDK 1708 Security Update for Windows Builds Type/Severity Security Advisory: Moderate Topic An update is now available for OpenJDKRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is ...
概述 Moderate: java-11-openjdk security and bug fix update 类型/严重性 Security Advisory: Moderate Red Hat Insights 补丁分析 识别并修复受此公告影响的系统。 查看受影响的系统 标题 An update for java-11-openjdk is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this up ...
Synopsis Moderate: java-11-openjdk security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for java-11-openjdk is now available for Red Hat Enterprise Linux 86 Extended Update SupportRed Hat ...
Synopsis Moderate: OpenJDK security update Type/Severity Security Advisory: Moderate Topic An update is now available for OpenJDKRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnera ...
Synopsis Moderate: java-17-openjdk security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for java-17-openjdk is now available for Red Hat Enterprise Linux 86 Extended Update SupportRed Hat Product Sec ...
Synopsis Moderate: java-11-openjdk security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for java-11-openjdk is now available for Red Hat Enterprise Linux 84 Advanced Mission Critical Updat ...
Synopsis Moderate: java-11-openjdk security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rate ...
Synopsis Moderate: java-17-openjdk security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for java-17-openjdk is now available for Red Hat Enterprise Linux 90 Extended Update SupportRed Hat Product Sec ...
Synopsis Moderate: OpenJDK 11020 Security Update for Windows Builds Type/Severity Security Advisory: Moderate Topic An update is now available for OpenJDKRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is ...
Synopsis Important: Release of OpenShift Serverless Logic 1300 SP1 security update Type/Severity Security Advisory: Important Topic Release of OpenShift Serverless Operator 1301 and OpenShift Serverless Logic 1300 SP1Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring S ...
Synopsis Moderate: java-11-openjdk security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for java-11-openjdk is now available for Red Hat Enterprise Linux 81 Update Services for SAP Solutio ...
Synopsis Moderate: Release of OpenShift Serverless 1291 Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Serverless version 1291 is now availableRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity ...
DescriptionThe MITRE CVE dictionary describes this issue as: hb-ot-layout-gsubgposhh in HarfBuzz through 600 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks ...
firefox-esr , thunderbird and nss only are affected by this package (CVE-2023-0767) hb-ot-layout-gsubgposhh in HarfBuzz through 600 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks (CVE-2023-25193) The Mozilla Foundation Security Advisory describes this flaw ...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Networking) Supported versions that are affected are Oracle Java SE: 11019, 1707, 2001; Oracle GraalVM Enterprise Edition: 20310, 2136, 2232; Oracle GraalVM for JDK: 1707 and 2001 Difficult to exploi ...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Networking) Supported versions that are affected are Oracle Java SE: 11019, 1707, 2001; Oracle GraalVM Enterprise Edition: 20310, 2136, 2232; Oracle GraalVM for JDK: 1707 and 2001 Difficult to exploi ...
Cosminexus Developer's Kit for Java(TM) and Hitachi Developer's Kit for Java contain the following vulnerabilities: CVE-2023-22006, CVE-2023-22036, CVE-2023-22041, CVE-2023-22044, CVE-2023-22045, CVE-2023-22049, CVE-2023-25193 Affected products and versions are listed below Please upgrade your version to the appropriate version These vulnera ...
Multiple vulnerabilities have been found in Hitachi Command Suite, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center CVE-2023-22006, CVE-2023-22036, CVE-2023-22041, CVE-2023-22043, CVE-2023-22044, CVE-2023-22045, CVE-2023-22049, CVE-2023-25193 Affected products and versi ...