Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10733

Опубликовано: 04 мая 2018
Источник: debian

Описание

There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libgxpsfixed0.3.0-3package
libgxpsno-dsastretchpackage
libgxpsno-dsajessiepackage
libgxpsignoredwheezypackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1574844

  • https://git.gnome.org/browse/libgxps/commit/?id=b458226e162fe1ffe7acb4230c114a52ada5131b

  • https://git.gnome.org/browse/libgxps/commit/?id=133fe2a96e020d4ca65c6f64fb28a404050ebbfd

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.

CVSS3: 3.3
redhat
больше 7 лет назад

There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.

CVSS3: 6.5
nvd
больше 7 лет назад

There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.

suse-cvrf
больше 6 лет назад

Security update for libgxps

suse-cvrf
больше 5 лет назад

Security update for libgxps