LWN.net Logo

pango: denial of service

Package(s):pango1.0 CVE #(s):CVE-2009-1194
Created:May 8, 2009 Updated:February 16, 2010
Description: From the Ubuntu advisory: Will Drewry discovered that Pango incorrectly handled rendering text with long glyphstrings. If a user were tricked into displaying specially crafted data with applications linked against Pango, such as Firefox, an attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program.
Alerts:
Mandriva MDVSA-2009:158-3 2009-12-03
SuSE SUSE-SR:2010:004 2010-02-16
Mandriva MDVSA-2009:158-2 2009-11-16
SuSE SUSE-SA:2009:042 2009-08-06
Mandriva MDVSA-2009:175 2009-07-29
Mandriva MDVSA-2009:158-1 2009-11-16
SuSE SUSE-SA:2009:039 2009-07-27
SuSE SUSE-SR:2009:012 2009-07-03
Debian DSA-1798-1 2009-05-10
CentOS CESA-2009:0476 2009-05-08
Red Hat RHSA-2009:0476-01 2009-05-08
Ubuntu USN-773-1 2009-05-07

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds