| From: |
| Meltem Parmaksız <meltem@pardus.org.tr> |
| To: |
| pardus-security@pardus.org.tr |
| Subject: |
| [Pardus-security] [PLSA 2011-58] Pango: Denial of Service |
| Date: |
| Mon, 21 Mar 2011 09:24:35 +0200 |
| Message-ID: |
| <201103210924.35652.meltem@pardus.org.tr> |
| Archive-link: |
| Article, Thread
|
------------------------------------------------------------------------
Pardus Linux Security Advisory 2011-58 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2011-03-21
Severity: 3
Type: Remote
------------------------------------------------------------------------
Summary
=======
A vulnerability has been fixed in pango, which can be used by malicious
people to cause denial of service.
Description
===========
CVE-2011-0064:
The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in
Pango 1.28.3, Firefox, and other products, does not verify that memory
reallocations succeed, which allows remote attackers to cause a denial
of service (NULL pointer dereference and application crash) or possibly
execute arbitrary code via crafted OpenType font data that triggers use
of an incorrect index.
Affected packages:
Pardus 2009:
pango, all before 1.26.2-36-12
Resolution
==========
There are update(s) for pango. You can update them via Package Manager
or with a single command from console:
pisi up pango
References
==========
* http://bugs.pardus.org.tr/show_bug.cgi?id=17221
* http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-...
------------------------------------------------------------------------
_______________________________________________
Pardus-Security mailing list
Pardus-Security@pardus.org.tr
http://liste.pardus.org.tr/mailman/listinfo/pardus-security
(
Log in to post comments)