PT-2011-1141 · Red Hat+1 · Frysk+2

Josh Bressers

·

Published

2011-09-21

·

Updated

2021-07-14

·

CVE-2011-3193

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qt versions prior to 4.7.4 Qt versions prior to 4.8.4 frysk version 0.0.1.2007.08.03
Description The issue is related to a heap-based buffer overflow in the Lookup MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), which can be exploited by remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For Qt versions prior to 4.7.4, update to version 4.7.4 or later to resolve the issue. For Qt versions prior to 4.8.4, update to version 4.8.4 or later to resolve the issue. For frysk version 0.0.1.2007.08.03, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-07205
BDU:2015-08790
BDU:2015-09706
CVE-2011-3193
DLA-117-1
OPENSUSE-SU-2024:10180-1
RHSA-2011:1323
RHSA-2011:1324
RHSA-2011:1325
RHSA-2011:1326
RHSA-2011:1327
RHSA-2011:1328
RHSA-2011_1323
RHSA-2011_1324
RHSA-2011_1325
RHSA-2011_1326
RHSA-2011_1327
RHSA-2011_1328

Affected Products

Qt
Red Hat
Frysk