PT-2010-5661 · Gnome+1 · Pango+1

Marc Schoenefeld

·

Published

1970-01-01

·

Updated

2021-07-14

·

CVE-2010-0421

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libpango1.0-0 versions prior to 1.27.1 libpango1.0-0-dbg versions prior to 1.27.1 libpango1.0-dev versions prior to 1.27.1 libpango1.0-doc versions prior to 1.27.1 libpango1.0-common versions prior to 1.27.1 libpango1.0-udeb versions prior to 1.27.1
Description The issue is related to multiple vulnerabilities in the Pango library, which can lead to a denial of service (application crash) when exploited. The vulnerabilities can be exploited remotely. Specifically, an array index error in the hb ot layout build glyph classes function in pango/opentype/hb-ot-layout.cc allows context-dependent attackers to cause a denial of service via a crafted font file.
Recommendations For libpango1.0-0 versions prior to 1.27.1, update to version 1.27.1 or later. For libpango1.0-0-dbg versions prior to 1.27.1, update to version 1.27.1 or later. For libpango1.0-dev versions prior to 1.27.1, update to version 1.27.1 or later. For libpango1.0-doc versions prior to 1.27.1, update to version 1.27.1 or later. For libpango1.0-common versions prior to 1.27.1, update to version 1.27.1 or later. For libpango1.0-udeb versions prior to 1.27.1, update to version 1.27.1 or later. As a temporary workaround, consider restricting access to crafted font files to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03310
BDU:2015-03311
BDU:2015-03312
BDU:2015-03313
BDU:2015-03314
BDU:2015-03315
CVE-2010-0421
DSA-2019-1
RHSA-2010:0140
RHSA-2010_0140

Affected Products

Pango
Red Hat