oss-sec mailing list archives
Re: CVE request: heap corruption in libpango
From: Josh Bressers <bressers () redhat com>
Date: Thu, 20 Jan 2011 11:36:48 -0500 (EST)
Please use CVE-2011-0020 for this. Thanks. -- JB ----- Original Message -----
From Launchpad [1]: "When used with FreeType2 as a backend, Pango is vulnerable to heap corruption when rendering malformed fonts. The vulnerability occurs in pango_ft2_font_render_box_glyph() in pango/pangoft2-render.c. A buffer is malloc'd with size box->bitmap.rows * box->bitmap.pitch. Subsequently, 0xff is written at offsets into this buffer without checking that these offsets fall within the buffer's boundaries, leading to heap corruption." -Dan [1] https://bugs.launchpad.net/ubuntu/+source/pango1.0/+bug/696616
Current thread:
- CVE request: heap corruption in libpango Dan Rosenberg (Jan 18)
- Re: CVE request: heap corruption in libpango Josh Bressers (Jan 20)