HarfBuzz contains an out-of-bounds read flaw in the 'tibetan_form' macro in harfbuzz-tibetan.c. With a specially crafted web page, a context-dependent attacker can cause a crash and potentially disclose memory contents.
Classification
Location:
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Availability
Solution:
Third-Party Solution,
Solution Unknown
Exploit:
PoC Public
Disclosure:
Third-party Verified
OSVDB:
Web Related
Solution
Upgrade to Google Chrome version 19.0.1084.46 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.