First published: Wed Nov 27 2019(Updated: )
In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns NULL).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME Font Viewer | =3.34.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19308 is classified as a moderate-severity vulnerability due to the potential for a NULL pointer dereference.
To fix CVE-2019-19308, upgrade to a version of GNOME Font Viewer that has addressed this vulnerability.
CVE-2019-19308 affects GNOME Font Viewer version 3.34.0.
CVE-2019-19308 is a NULL pointer dereference that occurs when parsing TTF font files lacking a name section.
While the exploitation of CVE-2019-19308 may cause an application crash, potential impacts depend on the context in which the vulnerable software is used.