Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-0020

Опубликовано: 24 янв. 2011
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.6

Описание

Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

1.28.3-4ubuntu1
hardy

released

1.20.5-0ubuntu1.2
karmic

released

1.26.0-1ubuntu0.1
lucid

released

1.28.0-0ubuntu2.2
maverick

released

1.28.2-0ubuntu1.1
upstream

needs-triage

Показывать по

EPSS

Процентиль: 92%
0.07842
Низкий

7.6 High

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.

nvd
больше 14 лет назад

Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.

debian
больше 14 лет назад

Heap-based buffer overflow in the pango_ft2_font_render_box_glyph func ...

github
около 3 лет назад

Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.

oracle-oval
больше 14 лет назад

ELSA-2011-0180: pango security update (MODERATE)

EPSS

Процентиль: 92%
0.07842
Низкий

7.6 High

CVSS2