|
|
Log in / Subscribe / Register

pango: denial of service

Package(s):pango CVE #(s):CVE-2010-0421
Created:March 16, 2010 Updated:March 2, 2011
Description: From the Red Hat advisory:

An input sanitization flaw, leading to an array index error, was found in the way the Pango font rendering library synthesized the Glyph Definition (GDEF) table from a font's character map and the Unicode property database. If an attacker created a specially-crafted font file and tricked a local, unsuspecting user into loading the font file in an application that uses the Pango font rendering library, it could cause that application to crash.

Alerts:
Ubuntu USN-1082-1 pango1.0 2011-03-02
Mandriva MDVSA-2010:121 pango 2010-06-22
SuSE SUSE-SR:2010:012 evolution-data-server, python/libpython2_6-1_0, mozilla-nss, memcached, texlive/te_ams, mono/bytefx-data-mysql, libpng-devel, apache2-mod_php5, ncpfs, pango, libcmpiutil 2010-05-25
SuSE SUSE-SR:2010:013 apache2-mod_php5/php5, bytefx-data-mysql/mono, flash-player, fuse, java-1_4_2-ibm, krb5, libcmpiutil/libvirt, libmozhelper-1_0-0/mozilla-xulrunner190, libopenssl-devel, libpng12-0, libpython2_6-1_0, libtheora, memcached, ncpfs, pango, puppet, python, seamonkey, te_ams, texlive 2010-06-14
SuSE SUSE-SR:2010:009 viewvc, krb5, pango, gimp, kdebase3, kde4-kdm 2010-04-14
Pardus 2010-40 pango-1.26.2-34-10 pango-1.21.3-28-8 2010-03-29
Debian DSA-2019-1 pango1.0 2010-03-20
CentOS CESA-2010:0140 pango 2010-03-16
Red Hat RHSA-2010:0140-01 pango 2010-03-15

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds