OSV-2023-160

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/harfbuzz/OSV-2023-160.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2023-160
Published
2023-03-10T13:01:50.295470Z
Modified
2023-03-10T13:01:50.295694Z
Summary
Global-buffer-overflow in OT::gvar::accelerator_t::apply_deltas_to_points
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=56800

Crash type: Global-buffer-overflow READ 2
Crash state:
OT::gvar::accelerator_t::apply_deltas_to_points
bool OT::glyf_impl::Glyph::get_points<OT::glyf_accelerator_t>
bool OT::glyf_impl::Glyph::get_points<OT::glyf_accelerator_t>
References

Affected packages

OSS-Fuzz / harfbuzz

Package

Name
harfbuzz
Purl
pkg:generic/harfbuzz

Affected ranges

Type
GIT
Repo
https://github.com/harfbuzz/harfbuzz.git
Events

Ecosystem specific

{
    "severity": null
}

Database specific

{
    "introduced_range": "b4b089c4278f041f69c3253f84901de226d38558:7327006d686c149cefdc7ee6047d2b426ac1ac75",
    "fixed_range": "7327006d686c149cefdc7ee6047d2b426ac1ac75:28b05e1cb6116b07b95af799ff68b883c3f590d1"
}