PT-2011-2018 · Gnome+1 · Pango+1

Jan Lieskovsky

·

Published

2011-01-24

·

Updated

2024-06-15

·

CVE-2011-0020

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pango versions 1.28.3 and earlier
Description The issue is related to a heap-based buffer overflow in the pango ft2 font render box glyph function, which can be triggered by a crafted font file when the FreeType2 backend is enabled. This can lead to a denial of service, causing the application to crash, or potentially allow the execution of arbitrary code. The problem is associated with the glyph box for an FT Bitmap object.
Recommendations For Pango versions 1.28.3 and earlier, consider updating to a newer version to resolve the issue. As a temporary workaround, restrict the use of crafted font files to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0020
OPENSUSE-SU-2024:10578-1
RHSA-2011:0180
RHSA-2011_0180

Affected Products

Pango
Red Hat