GNOME Pango 1.42.3

CPE Details

GNOME Pango 1.42.3
1.42.3
2021-07-14
13h38 +00:00
2021-07-14
13h41 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:gnome:pango:1.42.3:*:*:*:*:*:*:*

Informations

Vendor

gnome

Product

pango

Version

1.42.3

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-1010238 2019-07-19 14h42 +00:00 Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to functions like pango_itemize.
9.8
Critical
CVE-2018-15120 2018-08-24 17h00 +00:00 libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.
6.5
Medium