Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-1010238

Опубликовано: 06 авг. 2019
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to functions like pango_itemize.

A buffer overflow flaw was found in Gnome Pango. When invalid utf-8 strings are passed to functions, a heap-based buffer overflow can occur that could lead to code execution. The highest threat from this vulnerability is data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pangoNot affected
Red Hat Enterprise Linux 6pangoNot affected
Red Hat Enterprise Linux 7pangoFixedRHSA-2019:257128.08.2019
Red Hat Enterprise Linux 7.6 Extended Update SupportpangoFixedRHSA-2019:323429.10.2019
Red Hat Enterprise Linux 8pangoFixedRHSA-2019:258229.08.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1737785pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow

EPSS

Процентиль: 90%
0.05393
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to functions like pango_itemize.

CVSS3: 9.8
nvd
около 6 лет назад

Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to functions like pango_itemize.

CVSS3: 9.8
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 9.8
debian
около 6 лет назад

Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact ...

CVSS3: 9.8
github
больше 3 лет назад

Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to functions like pango_itemize.

EPSS

Процентиль: 90%
0.05393
Низкий

9.8 Critical

CVSS3