Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade evolution28-pango-develUpgrade evolution28-pango | Dec 1, 2016 | Jan 24, 2011 |
| Debian | — | Upgrade pango1.0 | Jul 30, 2024 | Jan 24, 2011 |
| Gentoo Linux | — | Upgrade x11-libs/pango. | Oct 30, 2017 | Jan 24, 2011 |
| Oracle_linux | — | Upgrade pangoUpgrade pango-devel | Oct 16, 2024 | Jan 24, 2011 |
| Suse | — | Upgrade pango-devel-32bitUpgrade pango-modules-32bitUpgrade pango-toolsUpgrade pangoUpgrade typelib-1_0-Pango-1_0Upgrade pango-modulesUpgrade pango-docUpgrade pango-x86Upgrade libpango-1_0-0Upgrade pango-develUpgrade libpango-1_0-0-32bitUpgrade pango-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gir1.0-pango-1.0Upgrade libpango1.0-0 | Nov 8, 2024 | Jan 24, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub