PT-2011-2018 · Gnome+1 · Pango+1

Jan Lieskovsky

·

Publicado

2011-01-24

·

Atualizado

2024-06-15

·

CVE-2011-0020

CVSS v2.0

7.6

Alta

VetorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pango versions 1.28.3 and earlier
Description The issue is related to a heap-based buffer overflow in the pango ft2 font render box glyph function, which can be triggered by a crafted font file when the FreeType2 backend is enabled. This can lead to a denial of service, causing the application to crash, or potentially allow the execution of arbitrary code. The problem is associated with the glyph box for an FT Bitmap object.
Recommendations For Pango versions 1.28.3 and earlier, consider updating to a newer version to resolve the issue. As a temporary workaround, restrict the use of crafted font files to minimize the risk of exploitation.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-0020
OPENSUSE-SU-2024:10578-1
RHSA-2011:0180
RHSA-2011_0180

Produtos afetados

Pango
Red Hat