First published: Fri Aug 24 2018(Updated: )
libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gnome Pango | >=1.40.8<=1.42.3 | |
Canonical Ubuntu Linux | =18.04 | |
ubuntu/pango1.0 | <1.40.14-1ubuntu0.1 | 1.40.14-1ubuntu0.1 |
ubuntu/pango1.0 | <1.42.4-1 | 1.42.4-1 |
debian/pango1.0 | 1.46.2-3 1.50.12+ds-1 1.54.0+ds-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15120 is a vulnerability in libpango, as used in hexchat and other products, that allows remote attackers to cause a denial of service or possibly have other impact via crafted text with invalid Unicode sequences.
CVE-2018-15120 affects libpango 1.40.8 through 1.42.3, as used in hexchat and other products.
CVE-2018-15120 has a severity rating of medium with a CVSS score of 6.5.
To fix CVE-2018-15120, update to version 1.42.4-1 or later of the pango1.0 package on Ubuntu, or apply the appropriate remedy provided by the respective software vendor.
You can find more information about CVE-2018-15120 in the provided references: https://mail.gnome.org/archives/distributor-list/2018-August/msg00001.html, https://github.com/GNOME/pango/blob/1.42.4/NEWS, https://github.com/GNOME/pango/commit/71aaeaf020340412b8d012fe23a556c0420eda5f