DEBIAN-CVE-2022-33047

Source
https://security-tracker.debian.org/tracker/CVE-2022-33047
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-33047.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2022-33047
Upstream
Published
2022-07-06T19:15:08.590Z
Modified
2026-03-17T02:47:27.005900Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.

References

Affected packages

Debian:12 / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/debian/texlive-bin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2022.*
2022.20220321.62855-5.1
2022.20220321.62855-5.1+deb12u1
2022.20220321.62855-5.1+deb12u2
2022.20220321.62855-6
2022.20220321.62855-7
2022.20220321.62855-8
2023.*
2023.20230311.66589-1
2023.20230311.66589-2
2023.20230311.66589-3
2023.20230311.66589-4
2023.20230311.66589-5
2023.20230311.66589-6
2023.20230311.66589-7
2023.20230311.66589-8
2023.20230311.66589-9
2024.*
2024.20240313.70630+ds-1
2024.20240313.70630+ds-2
2024.20240313.70630+ds-3
2024.20240313.70630+ds-4
2024.20240313.70630+ds-5
2024.20240313.70630+ds-6
2025.*
2025.20250727.75242+ds-1
2025.20250727.75242+ds-2
2025.20250727.75242+ds-3
2025.20250727.75242+ds-4
2025.20250727.75242+ds-5~hurd.1
2025.20250727.75242+ds-5

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-33047.json"

Debian:13 / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/debian/texlive-bin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2024.*
2024.20240313.70630+ds-6
2025.*
2025.20250727.75242+ds-1
2025.20250727.75242+ds-2
2025.20250727.75242+ds-3
2025.20250727.75242+ds-4
2025.20250727.75242+ds-5~hurd.1
2025.20250727.75242+ds-5

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-33047.json"

Debian:14 / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/debian/texlive-bin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2024.*
2024.20240313.70630+ds-6
2025.*
2025.20250727.75242+ds-1
2025.20250727.75242+ds-2
2025.20250727.75242+ds-3
2025.20250727.75242+ds-4
2025.20250727.75242+ds-5~hurd.1
2025.20250727.75242+ds-5

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-33047.json"