LWN.net Logo

pango: arbitrary code execution

Package(s):evolution28-pango pango qt CVE #(s):CVE-2011-3193
Created:September 23, 2011 Updated:September 23, 2011
Description: From the Red Hat advisory:

A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping engine used in Pango. If a user loaded a specially-crafted font file with an application that uses Pango, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application.

Alerts:
openSUSE openSUSE-SU-2011:1120-1 2011-10-12
openSUSE openSUSE-SU-2011:1119-1 2011-10-12
Red Hat RHSA-2011:1326-01 2011-09-21
CentOS CESA-2011:1324 2011-09-22
CentOS CESA-2011:1326 2011-09-22
Scientific Linux SL-qt-20110921 2011-09-21
Scientific Linux SL-qt4-20110921 2011-09-21
Scientific Linux SL-evol-20110921 2011-09-21
Scientific Linux SL-pang-20110921 2011-09-21
Scientific Linux SL-frys-20110921 2011-09-21
Red Hat RHSA-2011:1323-01 2011-09-21
Red Hat RHSA-2011:1324-01 2011-09-21
Red Hat RHSA-2011:1327-01 2011-09-21
CentOS CESA-2011:1327 2011-09-22
CentOS CESA-2011:1325 2011-09-22
Red Hat RHSA-2011:1325-01 2011-09-21
Ubuntu USN-1504-1 2012-07-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds