#VU72050 Input validation error in HarfBuzz - CVE-2023-25193
Published: February 8, 2023 / Updated: February 12, 2023
HarfBuzz
Freedesktop.org
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in hb-ot-layout-gsubgpos.hh. A remote attacker can use consecutive marks during the process of looking back for base glyphs when attaching marks and perform a denial of service (DoS) attack.