CVE-2011-0064

The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnome:pango:1.28.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

History

14 Jul 2021, 15:41

Type Values Removed Values Added
CPE cpe:2.3:a:pango:pango:1.28.3:*:*:*:*:*:*:* cpe:2.3:a:gnome:pango:1.28.3:*:*:*:*:*:*:*

Information

Published : 2011-03-07 21:00

Updated : 2023-12-10 11:03


NVD link : CVE-2011-0064

Mitre link : CVE-2011-0064

CVE.ORG link : CVE-2011-0064


JSON object : View

Products Affected

mozilla

  • firefox

gnome

  • pango