Oval Definition:oval:com.redhat.rhsa:def:20100140
Revision Date:2010-03-15Version:643
Title:RHSA-2010:0140: pango security update (Moderate)
Description:Pango is a library used for the layout and rendering of internationalized text.

  • An input sanitization flaw, leading to an array index error, was found in the way the Pango font rendering library synthesized the Glyph Definition (GDEF) table from a font's character map and the Unicode property database. If an attacker created a specially-crafted font file and tricked a local, unsuspecting user into loading the font file in an application that uses the Pango font rendering library, it could cause that application to crash. (CVE-2010-0421)

    Users of pango and evolution28-pango are advised to upgrade to these updated packages, which contain a backported patch to resolve this issue. After installing this update, you must restart your system or restart your X session for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-0421
    RHSA-2010:0140
    RHSA-2010:0140-01
    RHSA-2010:0140-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • pango-devel is earlier than 0:1.2.5-10
  • AND pango-devel is signed with Red Hat master key
  • pango is earlier than 0:1.2.5-10
  • AND pango is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • evolution28-pango is earlier than 0:1.14.9-13.el4_8
  • AND evolution28-pango is signed with Red Hat master key
  • evolution28-pango-devel is earlier than 0:1.14.9-13.el4_8
  • AND evolution28-pango-devel is signed with Red Hat master key
  • pango-devel is earlier than 0:1.6.0-16.el4_8
  • AND pango-devel is signed with Red Hat master key
  • pango is earlier than 0:1.6.0-16.el4_8
  • AND pango is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • pango-devel is earlier than 0:1.14.9-8.el5
  • AND pango-devel is signed with Red Hat redhatrelease key
  • pango is earlier than 0:1.14.9-8.el5
  • AND pango is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • pango is earlier than 0:1.2.5-10
  • AND pango is signed with Red Hat master key
  • pango-devel is earlier than 0:1.2.5-10
  • AND pango-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • evolution28-pango is earlier than 0:1.14.9-13.el4_8
  • AND evolution28-pango is signed with Red Hat master key
  • evolution28-pango-devel is earlier than 0:1.14.9-13.el4_8
  • AND evolution28-pango-devel is signed with Red Hat master key
  • pango is earlier than 0:1.6.0-16.el4_8
  • AND pango is signed with Red Hat master key
  • pango-devel is earlier than 0:1.6.0-16.el4_8
  • AND pango-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • pango is earlier than 0:1.14.9-8.el5
  • AND pango is signed with Red Hat redhatrelease key
  • pango-devel is earlier than 0:1.14.9-8.el5
  • AND pango-devel is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • evolution28-pango is earlier than 0:1.14.9-13.el4_8
  • AND evolution28-pango is signed with Red Hat redhatrelease2 key
  • evolution28-pango-devel is earlier than 0:1.14.9-13.el4_8
  • AND evolution28-pango-devel is signed with Red Hat redhatrelease2 key
  • pango is earlier than 0:1.6.0-16.el4_8
  • AND pango is signed with Red Hat redhatrelease2 key
  • pango-devel is earlier than 0:1.6.0-16.el4_8
  • AND pango-devel is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • pango is earlier than 0:1.14.9-8.el5
  • AND pango is signed with Red Hat redhatrelease2 key
  • pango-devel is earlier than 0:1.14.9-8.el5
  • AND pango-devel is signed with Red Hat redhatrelease2 key
  • BACK