Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-25193
Description:hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
Test IDs: 1.3.6.1.4.1.25623.1.1.18.1.2025.0067.1   1.3.6.1.4.1.25623.1.1.2.2023.3432   1.3.6.1.4.1.25623.1.0.827277   1.3.6.1.4.1.25623.1.1.2.2023.1955   1.3.6.1.4.1.25623.1.1.2.2023.2294   1.3.6.1.4.1.25623.1.0.827268   1.3.6.1.4.1.25623.1.1.18.1.2025.0066.1   1.3.6.1.4.1.25623.1.1.4.2023.1820.1   1.3.6.1.4.1.25623.1.1.2.2023.1871   1.3.6.1.4.1.25623.1.1.2.2023.1846   1.3.6.1.4.1.25623.1.1.2.2024.2269   1.3.6.1.4.1.25623.1.1.2.2024.1652   1.3.6.1.4.1.25623.1.1.2.2024.1142   1.3.6.1.4.1.25623.1.1.2.2023.1977   1.3.6.1.4.1.25623.1.1.4.2023.1821.1   1.3.6.1.4.1.25623.1.1.4.2023.1822.1   1.3.6.1.4.1.25623.1.0.827296   1.3.6.1.4.1.25623.1.1.12.2025.7251.1   1.3.6.1.4.1.25623.1.1.2.2023.2270   1.3.6.1.4.1.25623.1.0.827261   1.3.6.1.4.1.25623.1.1.2.2023.3129  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-25193
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KWCHWSICWVZSAXP2YAXM65JC2GR53547/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YZ5M2GSAIHFPLHYJXUPQ2QDJCLWXUGO3/
https://chromium.googlesource.com/chromium/src/+/e1f324aa681af54101c1f2d173d92adb80e37088/DEPS#361
https://github.com/harfbuzz/harfbuzz/blob/2822b589bc837fae6f66233e2cf2eef0f6ce8470/src/hb-ot-layout-gsubgpos.hh
https://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dc




© 1998-2025 E-Soft Inc. All rights reserved.