OSV-2022-108
Dashboard / Vulnerabilities / OSV-2022-108
OSV-2022-108
Published: 31 Jan 2022Last Modified: 18 Jul 2022
Summary: Heap-buffer-overflow in void apply_string<GSUBProxy>
Details: OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=44212 Crash type: Heap-buffer-overflow READ 2 Crash state: void apply_string<GSUBProxy> void hb_ot_map_t::apply<GSUBProxy> hb_ot_map_t::substitute
Affected packages
Package
Name: harfbuzz
Purl: pkg:generic/harfbuzz
Affected ranges
Type: GIT
Events:
Introduced- a75b96f7e5833c9206f6a15d11168a757a85ee59
Affected versions
3.1.2
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
