Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's charmap and the Unicode property database.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade pango-develUpgrade pango | Dec 1, 2016 | Mar 18, 2010 |
| Debian | — | Upgrade pango1.0 | Jul 30, 2024 | Mar 18, 2010 |
| Oracle_linux | — | Upgrade pango-develUpgrade pango | Oct 16, 2024 | Mar 18, 2010 |
| Suse | — | Upgrade pango-devel-64bitUpgrade pango-docUpgrade pangoUpgrade sap-aio-releaseUpgrade pango-x86Upgrade pango-develUpgrade pango-64bitUpgrade pango-32bit | Feb 17, 2015 | Mar 18, 2010 |
| Ubuntu | — | Upgrade gir1.0-pango-1.0Upgrade libpango1.0-0 | Nov 8, 2024 | Mar 18, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub