libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade pango | Nov 9, 2018 | Aug 24, 2018 |
| Debian | — | Upgrade pango1.0 | Jul 30, 2024 | Aug 24, 2018 |
| Freebsd | — | Upgrade pango | Oct 2, 2018 | Oct 1, 2018 |
| Gentoo Linux | — | Upgrade x11-libs/pango. | Nov 12, 2018 | Aug 24, 2018 |
| Suse | — | Upgrade pango-toolsUpgrade libpango-1_0-0-32bitUpgrade typelib-1_0-Pango-1_0Upgrade pango-develUpgrade pango-devel-32bitUpgrade libpango-1_0-0 | Sep 22, 2018 | Aug 24, 2018 |
| Ubuntu | — | Upgrade gir1.2-pango-1.0Upgrade libpango1.0-0Upgrade libpango-1.0-0 | Aug 30, 2018 | Aug 22, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub