Gentoo alert 202407-24 (HarfBuzz)
| From: | glsamaker@gentoo.org | |
| To: | gentoo-announce@lists.gentoo.org | |
| Subject: | [gentoo-announce] [ GLSA 202407-24 ] HarfBuzz: Denial of Service | |
| Date: | Wed, 10 Jul 2024 06:11:40 -0000 | |
| Message-ID: | <172059190035.7.14697862664777756517@3f85d36892cf> |
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202407-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: HarfBuzz: Denial of Service Date: July 10, 2024 Bugs: #905310 ID: 202407-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in HarfBuzz, which can lead to a denial of service. Background ========== HarfBuzz is an OpenType text shaping engine. Affected packages ================= Package Vulnerable Unaffected ------------------- ------------ ------------ media-libs/harfbuzz < 7.1.0 >= 7.1.0 Description =========== Multiple vulnerabilities have been discovered in HarfBuzz. Please review the CVE identifiers referenced below for details. Impact ====== hb-ot-layout-gsubgpos.hh in HarfBuzz allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks. Workaround ========== There is no known workaround at this time. Resolution ========== All HarfBuzz users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=media-libs/harfbuzz-7.1.0" References ========== [ 1 ] CVE-2023-22006 https://nvd.nist.gov/vuln/detail/CVE-2023-22006 [ 2 ] CVE-2023-22036 https://nvd.nist.gov/vuln/detail/CVE-2023-22036 [ 3 ] CVE-2023-22041 https://nvd.nist.gov/vuln/detail/CVE-2023-22041 [ 4 ] CVE-2023-22044 https://nvd.nist.gov/vuln/detail/CVE-2023-22044 [ 5 ] CVE-2023-22045 https://nvd.nist.gov/vuln/detail/CVE-2023-22045 [ 6 ] CVE-2023-22049 https://nvd.nist.gov/vuln/detail/CVE-2023-22049 [ 7 ] CVE-2023-25193 https://nvd.nist.gov/vuln/detail/CVE-2023-25193 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202407-24 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmaOJhwACgkQFMQkOaVy +9nqJQ/+NOas6BQsupzoIXW+pum0xa/doOtTORPmB+jAPXF6yFLdBp3UusQ584iX dAuVMovyK7p6TfFxJd1PZp8JEwZGtGJQSdd2D4y9bnWiljTRMdbbJq0U81zr+N50 D27XgqB2JcMNVyQ6qfufUuKfFRuSXOPwQDGNAT7reERYoGA9hHi9+VFzKOge22DZ xoZ2alX5u5JLBv9i0oZATyAun4k/JJcnk+C3FPflsx+MEKD0gneDNrNG/4r9Y+iT 7fyWgyAXDlOBGyvF5RL7K+UMJCA/BtjHnL5RZpUZnVOOVKy4sh1DgXKngAJMzSl6 Xp1rA6gYABLQrqn5LvTF15DaVMBjwj7VIz76pfBDByuk7nRTXZVQ0yvCT91gfSxe 4z1MG7EsclHdYYCUErXx7GcIp3v9nGAAaGHvyZdOqoS6b1aU52JljfWS+KgWvSku 8h6zHDeX3QgQutXL2WrJs0qvAYhiif+e6D88R4AbddFqUCjOGk7N/15HXA4IUHW0 e7pSzI6LEF0RZjQ7qxh8nwnEHzvyfN+tF917ZkBuOLNDEwuKgISgHjpvs4oHj97f +fbS8f2UwnANTZZPI3PfxaK3XoOWdN00TyOtdRioa2YyUws01qi4hcFFDPx9yCGn QCNxHzsMfTxYjnZkvepy3oTlqYDHq4YBPo0cPhfysTM79WJszeg= =uR7Q -----END PGP SIGNATURE-----
