Back

MEDIUM

pango: pango_glyph_string_set_size integer overflow

Published May 11, 2009

Description

Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long glyph string that triggers a heap-based buffer overflow, as demonstrated by a long document.location value in Firefox.

Affected products

Remediation

No remediation recorded yet.

References (34)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 11, 2009
Updated Aug 7, 2024
Reserved Mar 31, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date May 7, 2009