Hi, On Sun, Feb 05, 2023 at 05:30:39PM +0100, Salvatore Bonaccorso wrote: > Source: harfbuzz > Version: 6.0.0+dfsg-3 > Severity: important > Tags: security upstream > X-Debbugs-Cc: [email protected], Debian Security Team > <[email protected]> > > Hi, > > The following vulnerability was published for harfbuzz. > > CVE-2023-25193[0]: > | hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to > | trigger O(n^2) growth via consecutive marks during the process of > | looking back for base glyphs when attaching marks. > > > If you fix the vulnerability please also make sure to include the > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. > > For further information see: > > [0] https://security-tracker.debian.org/tracker/CVE-2023-25193 > https://www.cve.org/CVERecord?id=CVE-2023-25193 > [1] > https://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dc
The [1] commit has later on been reverted again, and replaced by https://github.com/harfbuzz/harfbuzz/commit/8708b9e081192786c027bb7f5f23d76dbe5c19e8 . See https://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dc#commitcomment-101335712 Regards, Salvatore

