Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pango HarfBuzz模块缓冲区错误漏洞
Vulnerability Description
Pango是一个开放源码的自由函数库,用于高质量地渲染国际化的文字。 使用在Qt 4.7.4之前版本和Pango中的HarfBuzz(harfbuzz-gpos.c)模块中的Lookup_MarkMarkPos函数中存在基于堆的缓冲区溢出漏洞。远程攻击者可利用该漏洞通过特制的字体文件导致拒绝服务(崩溃),执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A