ZeroHour

CVE-2019-1010238

PoC
CVSS 3.1
9.8 critical
EPSS
6%p93
Published
()
Modified
Description

Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to functions like pango_itemize.

Vendors
gnomeoraclefedoraprojectdebiancanonicalredhat
Products
pango, sd-wan edge, fedora, debian linux, ubuntu linux, openshift container platform, enterprise linux, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.