Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-3193
Description:Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
Test IDs: 1.3.6.1.4.1.25623.1.0.70436   1.3.6.1.4.1.25623.1.0.870488   1.3.6.1.4.1.25623.1.0.881308   1.3.6.1.4.1.25623.1.0.70435   1.3.6.1.4.1.25623.1.0.880999   1.3.6.1.4.1.25623.1.0.881426   1.3.6.1.4.1.25623.1.0.880997   1.3.6.1.4.1.25623.1.0.881297   1.3.6.1.4.1.25623.1.0.870492   1.3.6.1.4.1.25623.1.1.1.2.2014.117   1.3.6.1.4.1.25623.1.0.70296   1.3.6.1.4.1.25623.1.0.881009   1.3.6.1.4.1.25623.1.0.122085   1.3.6.1.4.1.25623.1.0.70418   1.3.6.1.4.1.25623.1.0.870490   1.3.6.1.4.1.25623.1.0.70297   1.3.6.1.4.1.25623.1.0.70295   1.3.6.1.4.1.25623.1.0.122084  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-3193
41537
http://secunia.com/advisories/41537
46117
http://secunia.com/advisories/46117
46118
http://secunia.com/advisories/46118
46119
http://secunia.com/advisories/46119
46128
http://secunia.com/advisories/46128
46371
http://secunia.com/advisories/46371
46410
http://secunia.com/advisories/46410
49723
http://www.securityfocus.com/bid/49723
49895
http://secunia.com/advisories/49895
75652
http://www.osvdb.org/75652
RHSA-2011:1323
http://rhn.redhat.com/errata/RHSA-2011-1323.html
RHSA-2011:1324
http://rhn.redhat.com/errata/RHSA-2011-1324.html
RHSA-2011:1325
http://rhn.redhat.com/errata/RHSA-2011-1325.html
RHSA-2011:1326
http://rhn.redhat.com/errata/RHSA-2011-1326.html
RHSA-2011:1327
http://rhn.redhat.com/errata/RHSA-2011-1327.html
RHSA-2011:1328
http://rhn.redhat.com/errata/RHSA-2011-1328.html
SUSE-SU-2011:1113
https://hermes.opensuse.org/messages/12056605
USN-1504-1
http://www.ubuntu.com/usn/USN-1504-1
[oss-security] 20120822 CVE request: libqt4: two memory issues
http://www.openwall.com/lists/oss-security/2011/08/22/6
[oss-security] 20120824 Re: CVE request: libqt4: two memory issues
http://www.openwall.com/lists/oss-security/2011/08/24/8
[oss-security] 20120825 Re: CVE request: libqt4: two memory issues
http://www.openwall.com/lists/oss-security/2011/08/25/1
http://cgit.freedesktop.org/harfbuzz.old/commit/?id=81c8ef785b079980ad5b46be4fe7c7bf156dbf65
http://cgit.freedesktop.org/harfbuzz.old/commit/?id=81c8ef785b079980ad5b46be4fe7c7bf156dbf65
http://cgit.freedesktop.org/harfbuzz/commit/src/harfbuzz-gpos.c?id=da2c52abcd75d46929b34cad55c4fb2c8892bc08
http://cgit.freedesktop.org/harfbuzz/commit/src/harfbuzz-gpos.c?id=da2c52abcd75d46929b34cad55c4fb2c8892bc08
http://git.gnome.org/browse/pango/commit/pango/opentype/harfbuzz-gpos.c?id=a7a715480db66148b1f487528887508a7991dcd0
http://git.gnome.org/browse/pango/commit/pango/opentype/harfbuzz-gpos.c?id=a7a715480db66148b1f487528887508a7991dcd0
https://qt.gitorious.org/qt/qt/commit/9ae6f2f9a57f0c3096d5785913e437953fa6775c
https://qt.gitorious.org/qt/qt/commit/9ae6f2f9a57f0c3096d5785913e437953fa6775c
openSUSE-SU-2011:1119
http://lists.opensuse.org/opensuse-updates/2011-10/msg00007.html
openSUSE-SU-2011:1120
http://lists.opensuse.org/opensuse-updates/2011-10/msg00008.html
pango-harfbuzz-bo(69991)
https://exchange.xforce.ibmcloud.com/vulnerabilities/69991




© 1998-2025 E-Soft Inc. All rights reserved.