PT-2011-2018 · Gnome+1 · Pango+1
Jan Lieskovsky
·
Published
2011-01-24
·
Updated
2024-06-15
·
CVE-2011-0020
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Pango versions 1.28.3 and earlier
Description
The issue is related to a heap-based buffer overflow in the
pango ft2 font render box glyph function, which can be triggered by a crafted font file when the FreeType2 backend is enabled. This can lead to a denial of service, causing the application to crash, or potentially allow the execution of arbitrary code. The problem is associated with the glyph box for an FT Bitmap object.Recommendations
For Pango versions 1.28.3 and earlier, consider updating to a newer version to resolve the issue. As a temporary workaround, restrict the use of crafted font files to minimize the risk of exploitation.
Exploit
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pango
Red Hat