CVE-2011-3193

Pango - Heap-Based Buffer Overflow in HarfBuzz Module via Crafted Font File

Title source: llm
STIX 2.1

Description

Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.

References (28)

Core 28
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46371
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1504-1
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/08/24/8
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2011-10/msg00007.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/41537
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46410
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2011-1327.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2011-1325.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/08/22/6
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46128
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2011-1324.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/08/25/1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49895
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46117
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2011-1326.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46119
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/49723
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2011-1323.html
Broken Link vendor-advisory x_refsource_suse
https://hermes.opensuse.org/messages/12056605
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2011-1328.html
Broken Link vdb-entry x_refsource_osvdb
http://www.osvdb.org/75652
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46118
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/69991
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2011-10/msg00008.html

Scores

EPSS 0.0973
EPSS Percentile 93.0%

Details

CWE
CWE-787
Status published
Products (16)
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 11.04
gnome/pango < 1.25.1
opensuse/opensuse 11.3
opensuse/opensuse 11.4
qt/qt < 4.7.4
redhat/enterprise_linux_desktop 4.0
redhat/enterprise_linux_desktop 5.0
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_eus 6.1
... and 6 more
Published Jun 16, 2012
Tracked Since Feb 18, 2026