Vulnerability Name: | CVE-2010-0421 (CCN-57048) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2010-03-15 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2010-03-15 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2021-07-14 | ||||||||||||||||||||||||||||||||||||||||
Summary: | Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's charmap and the Unicode property database. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.2 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2010-0421 Source: CONFIRM Type: Patch http://ftp.gnome.org/pub/GNOME/sources/pango/1.27/pango-1.27.1.tar.bz2 Source: SUSE Type: UNKNOWN SUSE-SR:2010:009 Source: SUSE Type: UNKNOWN SUSE-SR:2010:012 Source: SUSE Type: UNKNOWN SUSE-SR:2010:013 Source: CCN Type: RHSA-2010-0140 Moderate: pango security update Source: SECUNIA Type: UNKNOWN 39041 Source: CCN Type: SA39770 Avaya Products Pango Denial of Service Vulnerability Source: CCN Type: SA40504 Sun Solaris Pango Denial of Service Vulnerability Source: CCN Type: SECTRACK ID: 1023711 Pango GDEF Array Indexing Error in Font Library Lets Users Deny Service Source: SECTRACK Type: UNKNOWN 1023711 Source: DEBIAN Type: UNKNOWN DSA-2019 Source: DEBIAN Type: DSA-2019 pango1.0 -- missing input sanitization Source: MANDRIVA Type: UNKNOWN MDVSA-2010:121 Source: CCN Type: OSVDB ID: 63090 Pango pango/opentype/hb-ot-layout.cc hb_ot_layout_build_glyph_classes Function GDEF Table DoS Source: CCN Type: Pango Web site Pango Source: REDHAT Type: UNKNOWN RHSA-2010:0140 Source: BID Type: UNKNOWN 38760 Source: CCN Type: BID-38760 Pango Glyph Definition Table Denial of Service Vulnerability Source: VUPEN Type: UNKNOWN ADV-2010-0627 Source: VUPEN Type: UNKNOWN ADV-2010-0661 Source: VUPEN Type: UNKNOWN ADV-2010-1552 Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=555831 Source: XF Type: UNKNOWN pango-hbotlayoutbuildglyphclasses-dos(57048) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9417 Source: CCN Type: ASA-2010-137 pango security update (RHSA-2010-0140) Source: SUSE Type: SUSE-SR:2010:009 SUSE Security Summary Report Source: SUSE Type: SUSE-SR:2010:013 SUSE Security Summary Report | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: Configuration RedHat 9: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |