Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23723
HistoryApr 10, 2020 - 12:34 a.m.

Arbitrary Code Execution

2020-04-1000:34:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.004

Percentile

72.5%

pango is vulnerable to arbitrary code execution. The vulnerability exists as an integer overflow flaw in Pango’s pango_glyph_string_set_size() function. If an attacker is able to pass an arbitrarily long string to Pango, it may be possible to execute arbitrary code with the permissions of the application calling Pango.

References