2019-08-19
ALT-BU-2019-3883-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Published: 2019-07-19
BDU:2019-02871
Уязвимость функции pango_log2vis_get_embedding_levels библиотеки Pango, позволяющая нарушителю выполнить произвольный код
Severity: CRITICAL (9.8)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2019-07-19
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-1010238
Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to functions like pango_itemize.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- RHBA-2019:2824
- RHBA-2019:2824
- RHSA-2019:2571
- RHSA-2019:2571
- RHSA-2019:2582
- RHSA-2019:2582
- RHSA-2019:2594
- RHSA-2019:2594
- RHSA-2019:3234
- RHSA-2019:3234
- https://gitlab.gnome.org/GNOME/pango/-/commits/main/pango/pango-bidi-type.c
- https://gitlab.gnome.org/GNOME/pango/-/commits/main/pango/pango-bidi-type.c
- https://gitlab.gnome.org/GNOME/pango/-/issues/342
- https://gitlab.gnome.org/GNOME/pango/-/issues/342
- FEDORA-2019-547be4a683
- FEDORA-2019-547be4a683
- FEDORA-2019-155e34df5a
- FEDORA-2019-155e34df5a
- 20190812 [SECURITY] [DSA 4496-1] pango1.0 security update
- 20190812 [SECURITY] [DSA 4496-1] pango1.0 security update
- GLSA-201909-03
- GLSA-201909-03
- USN-4081-1
- USN-4081-1
- DSA-4496
- DSA-4496
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpuapr2020.html