CVE-2018-15120: Buffer Overflow
Last updated 25 August 2025
Other sources
libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-15120?
CVE-2018-15120 is a vulnerability in libpango, as used in hexchat and other products, that allows remote attackers to cause a denial of service or possibly have other impact via crafted text with invalid Unicode sequences.
Which software products are affected by CVE-2018-15120?
CVE-2018-15120 affects libpango 1.40.8 through 1.42.3, as used in hexchat and other products.
What is the severity of CVE-2018-15120?
CVE-2018-15120 has a severity rating of medium with a CVSS score of 6.5.
How can I fix CVE-2018-15120?
To fix CVE-2018-15120, update to version 1.42.4-1 or later of the pango1.0 package on Ubuntu, or apply the appropriate remedy provided by the respective software vendor.
Where can I find more information about CVE-2018-15120?
You can find more information about CVE-2018-15120 in the provided references: https://mail.gnome.org/archives/distributor-list/2018-August/msg00001.html, https://github.com/GNOME/pango/blob/1.42.4/NEWS, https://github.com/GNOME/pango/commit/71aaeaf020340412b8d012fe23a556c0420eda5f