跳转到帖子

Alma Linux: CVE-2023-25193: Moderate: harfbuzz security update (Multiple Advisories)

recommended_posts

发布于
  • Members

Alma Linux: CVE-2023-25193: Moderate: harfbuzz security update (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
02/04/2023
Created
07/25/2023
Added
07/24/2023
Modified
01/28/2025

Description

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

Solution(s)

  • alma-upgrade-harfbuzz
  • alma-upgrade-harfbuzz-devel
  • alma-upgrade-harfbuzz-icu
  • alma-upgrade-java-11-openjdk
  • alma-upgrade-java-11-openjdk-demo
  • alma-upgrade-java-11-openjdk-demo-fastdebug
  • alma-upgrade-java-11-openjdk-demo-slowdebug
  • alma-upgrade-java-11-openjdk-devel
  • alma-upgrade-java-11-openjdk-devel-fastdebug
  • alma-upgrade-java-11-openjdk-devel-slowdebug
  • alma-upgrade-java-11-openjdk-fastdebug
  • alma-upgrade-java-11-openjdk-headless
  • alma-upgrade-java-11-openjdk-headless-fastdebug
  • alma-upgrade-java-11-openjdk-headless-slowdebug
  • alma-upgrade-java-11-openjdk-javadoc
  • alma-upgrade-java-11-openjdk-javadoc-zip
  • alma-upgrade-java-11-openjdk-jmods
  • alma-upgrade-java-11-openjdk-jmods-fastdebug
  • alma-upgrade-java-11-openjdk-jmods-slowdebug
  • alma-upgrade-java-11-openjdk-slowdebug
  • alma-upgrade-java-11-openjdk-src
  • alma-upgrade-java-11-openjdk-src-fastdebug
  • alma-upgrade-java-11-openjdk-src-slowdebug
  • alma-upgrade-java-11-openjdk-static-libs
  • alma-upgrade-java-11-openjdk-static-libs-fastdebug
  • alma-upgrade-java-11-openjdk-static-libs-slowdebug
  • alma-upgrade-java-17-openjdk
  • alma-upgrade-java-17-openjdk-demo
  • alma-upgrade-java-17-openjdk-demo-fastdebug
  • alma-upgrade-java-17-openjdk-demo-slowdebug
  • alma-upgrade-java-17-openjdk-devel
  • alma-upgrade-java-17-openjdk-devel-fastdebug
  • alma-upgrade-java-17-openjdk-devel-slowdebug
  • alma-upgrade-java-17-openjdk-fastdebug
  • alma-upgrade-java-17-openjdk-headless
  • alma-upgrade-java-17-openjdk-headless-fastdebug
  • alma-upgrade-java-17-openjdk-headless-slowdebug
  • alma-upgrade-java-17-openjdk-javadoc
  • alma-upgrade-java-17-openjdk-javadoc-zip
  • alma-upgrade-java-17-openjdk-jmods
  • alma-upgrade-java-17-openjdk-jmods-fastdebug
  • alma-upgrade-java-17-openjdk-jmods-slowdebug
  • alma-upgrade-java-17-openjdk-slowdebug
  • alma-upgrade-java-17-openjdk-src
  • alma-upgrade-java-17-openjdk-src-fastdebug
  • alma-upgrade-java-17-openjdk-src-slowdebug
  • alma-upgrade-java-17-openjdk-static-libs
  • alma-upgrade-java-17-openjdk-static-libs-fastdebug
  • alma-upgrade-java-17-openjdk-static-libs-slowdebug

References

  • https://attackerkb.com/topics/cve-2023-25193
  • CVE - 2023-25193
  • https://errata.almalinux.org/8/ALSA-2023-4159.html
  • https://errata.almalinux.org/8/ALSA-2023-4175.html
  • https://errata.almalinux.org/8/ALSA-2024-2980.html
  • https://errata.almalinux.org/9/ALSA-2023-4158.html
  • https://errata.almalinux.org/9/ALSA-2023-4177.html
  • https://errata.almalinux.org/9/ALSA-2024-2410.html
View more
  • 查看数 696
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…