Note:
This project will be discontinued after December 13, 2021. [more]
2018-08-24
libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.
Products | Ubuntu_linux, Pango |
Type | Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) |
First patch |
https://github.com/GNOME/pango/commit/71aaeaf020340412b8d012fe23a556c0420eda5f |
Relevant file/s | ./pango/pango-emoji.c (modified, +6) |
Links |
• https://github.com/GNOME/pango/blob/1.42.4/NEWS
• https://i.redd.it/v7p4n2ptu0s11.jpg • https://www.exploit-db.com/exploits/45263/ • https://www.reddit.com/r/PS4/comments/9o5efg/message_bricking_console_megathread/ • https://www.ign.com/articles/2018/10/16/ps4s-are-reportedly-being-bricked-and-sony-is-working-on-a-fix |
Navigation
Patch data:
Patched area:
(on by default)
Patched area: