{ "CVE_data_meta" : { "ASSIGNER" : "cve@mitre.org", "ID" : "CVE-2011-3193", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "n/a", "version" : { "version_data" : [ { "version_value" : "n/a" } ] } } ] }, "vendor_name" : "n/a" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "n/a" } ] } ] }, "references" : { "reference_data" : [ { "name" : "[oss-security] 20120822 CVE request: libqt4: two memory issues", "refsource" : "MLIST", "url" : "http://www.openwall.com/lists/oss-security/2011/08/22/6" }, { "name" : "[oss-security] 20120824 Re: CVE request: libqt4: two memory issues", "refsource" : "MLIST", "url" : "http://www.openwall.com/lists/oss-security/2011/08/24/8" }, { "name" : "[oss-security] 20120825 Re: CVE request: libqt4: two memory issues", "refsource" : "MLIST", "url" : "http://www.openwall.com/lists/oss-security/2011/08/25/1" }, { "name" : "http://cgit.freedesktop.org/harfbuzz/commit/src/harfbuzz-gpos.c?id=da2c52abcd75d46929b34cad55c4fb2c8892bc08", "refsource" : "MISC", "url" : "http://cgit.freedesktop.org/harfbuzz/commit/src/harfbuzz-gpos.c?id=da2c52abcd75d46929b34cad55c4fb2c8892bc08" }, { "name" : "http://git.gnome.org/browse/pango/commit/pango/opentype/harfbuzz-gpos.c?id=a7a715480db66148b1f487528887508a7991dcd0", "refsource" : "MISC", "url" : "http://git.gnome.org/browse/pango/commit/pango/opentype/harfbuzz-gpos.c?id=a7a715480db66148b1f487528887508a7991dcd0" }, { "name" : "http://cgit.freedesktop.org/harfbuzz.old/commit/?id=81c8ef785b079980ad5b46be4fe7c7bf156dbf65", "refsource" : "CONFIRM", "url" : "http://cgit.freedesktop.org/harfbuzz.old/commit/?id=81c8ef785b079980ad5b46be4fe7c7bf156dbf65" }, { "name" : "https://qt.gitorious.org/qt/qt/commit/9ae6f2f9a57f0c3096d5785913e437953fa6775c", "refsource" : "CONFIRM", "url" : "https://qt.gitorious.org/qt/qt/commit/9ae6f2f9a57f0c3096d5785913e437953fa6775c" }, { "name" : "RHSA-2011:1323", "refsource" : "REDHAT", "url" : "http://rhn.redhat.com/errata/RHSA-2011-1323.html" }, { "name" : "RHSA-2011:1324", "refsource" : "REDHAT", "url" : "http://rhn.redhat.com/errata/RHSA-2011-1324.html" }, { "name" : "RHSA-2011:1325", "refsource" : "REDHAT", "url" : "http://rhn.redhat.com/errata/RHSA-2011-1325.html" }, { "name" : "RHSA-2011:1326", "refsource" : "REDHAT", "url" : "http://rhn.redhat.com/errata/RHSA-2011-1326.html" }, { "name" : "RHSA-2011:1327", "refsource" : "REDHAT", "url" : "http://rhn.redhat.com/errata/RHSA-2011-1327.html" }, { "name" : "RHSA-2011:1328", "refsource" : "REDHAT", "url" : "http://rhn.redhat.com/errata/RHSA-2011-1328.html" }, { "name" : "SUSE-SU-2011:1113", "refsource" : "SUSE", "url" : "https://hermes.opensuse.org/messages/12056605" }, { "name" : "openSUSE-SU-2011:1119", "refsource" : "SUSE", "url" : "http://lists.opensuse.org/opensuse-updates/2011-10/msg00007.html" }, { "name" : "openSUSE-SU-2011:1120", "refsource" : "SUSE", "url" : "http://lists.opensuse.org/opensuse-updates/2011-10/msg00008.html" }, { "name" : "USN-1504-1", "refsource" : "UBUNTU", "url" : "http://www.ubuntu.com/usn/USN-1504-1" }, { "name" : "49723", "refsource" : "BID", "url" : "http://www.securityfocus.com/bid/49723" }, { "name" : "75652", "refsource" : "OSVDB", "url" : "http://www.osvdb.org/75652" }, { "name" : "41537", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/41537" }, { "name" : "46117", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/46117" }, { "name" : "46118", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/46118" }, { "name" : "46119", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/46119" }, { "name" : "46128", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/46128" }, { "name" : "46371", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/46371" }, { "name" : "46410", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/46410" }, { "name" : "49895", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/49895" }, { "name" : "pango-harfbuzz-bo(69991)", "refsource" : "XF", "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/69991" } ] } }