PT-2011-1141 · Red Hat+1 · Frysk+2

Josh Bressers

·

Publicado

2011-09-21

·

Atualizado

2021-07-14

·

CVE-2011-3193

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qt versions prior to 4.7.4 Qt versions prior to 4.8.4 frysk version 0.0.1.2007.08.03
Description The issue is related to a heap-based buffer overflow in the Lookup MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), which can be exploited by remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For Qt versions prior to 4.7.4, update to version 4.7.4 or later to resolve the issue. For Qt versions prior to 4.8.4, update to version 4.8.4 or later to resolve the issue. For frysk version 0.0.1.2007.08.03, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-07205
BDU:2015-08790
BDU:2015-09706
CVE-2011-3193
DLA-117-1
OPENSUSE-SU-2024:10180-1
RHSA-2011:1323
RHSA-2011:1324
RHSA-2011:1325
RHSA-2011:1326
RHSA-2011:1327
RHSA-2011:1328
RHSA-2011_1323
RHSA-2011_1324
RHSA-2011_1325
RHSA-2011_1326
RHSA-2011_1327
RHSA-2011_1328

Produtos afetados

Qt
Red Hat
Frysk