CVE-2018-15120

libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnome:pango:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

History

14 Jul 2021, 15:41

Type Values Removed Values Added
CPE cpe:2.3:a:pango:pango:*:*:*:*:*:*:*:* cpe:2.3:a:gnome:pango:*:*:*:*:*:*:*:*

Information

Published : 2018-08-24 19:29

Updated : 2024-02-04 20:03


NVD link : CVE-2018-15120

Mitre link : CVE-2018-15120

CVE.ORG link : CVE-2018-15120


JSON object : View

Products Affected

canonical

  • ubuntu_linux

gnome

  • pango
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer