Lucene search

K
redhatRedHatRHSA-2010:0140
HistoryMar 15, 2010 - 12:00 a.m.

(RHSA-2010:0140) Moderate: pango security update

2010-03-1500:00:00
access.redhat.com
18

0.003 Low

EPSS

Percentile

65.1%

Pango is a library used for the layout and rendering of internationalized
text.

An input sanitization flaw, leading to an array index error, was found in
the way the Pango font rendering library synthesized the Glyph Definition
(GDEF) table from a font’s character map and the Unicode property database.
If an attacker created a specially-crafted font file and tricked a local,
unsuspecting user into loading the font file in an application that uses
the Pango font rendering library, it could cause that application to crash.
(CVE-2010-0421)

Users of pango and evolution28-pango are advised to upgrade to these
updated packages, which contain a backported patch to resolve this issue.
After installing this update, you must restart your system or restart your
X session for this update to take effect.