Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.69139
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-1082-1 (pango1.0)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to pango1.0
announced via advisory USN-1082-1.

Details follow:

Marc Schoenefeld discovered that Pango incorrectly handled certain Glyph
Definition (GDEF) tables. If a user were tricked into displaying text with
a specially-crafted font, an attacker could cause Pango to crash, resulting
in a denial of service. This issue only affected Ubuntu 8.04 LTS and 9.10.
(CVE-2010-0421)

Dan Rosenberg discovered that Pango incorrectly handled certain FT_Bitmap
objects. If a user were tricked into displaying text with a specially-
crafted font, an attacker could cause a denial of service or execute
arbitrary code with privileges of the user invoking the program. The
default compiler options for affected releases should reduce the
vulnerability to a denial of service. (CVE-2011-0020)

It was discovered that Pango incorrectly handled certain memory
reallocation failures. If a user were tricked into displaying text in a way
that would cause a reallocation failure, an attacker could cause a denial
of service or execute arbitrary code with privileges of the user invoking
the program. This issue only affected Ubuntu 9.10, 10.04 LTS and 10.10.
(CVE-2011-0064)

Solution:
The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.04 LTS:
libpango1.0-0 1.20.5-0ubuntu1.2

Ubuntu 9.10:
libpango1.0-0 1.26.0-1ubuntu0.1

Ubuntu 10.04 LTS:
gir1.0-pango-1.0 1.28.0-0ubuntu2.2

Ubuntu 10.10:
gir1.0-pango-1.0 1.28.2-0ubuntu1.1

After a standard system update you need to restart your session to make
all the necessary changes.

http://www.securityspace.com/smysecure/catid.html?in=USN-1082-1

Risk factor : High

CVSS Score:
7.6

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-0421
1023711
http://securitytracker.com/id?1023711
38760
http://www.securityfocus.com/bid/38760
39041
http://secunia.com/advisories/39041
ADV-2010-0627
http://www.vupen.com/english/advisories/2010/0627
ADV-2010-0661
http://www.vupen.com/english/advisories/2010/0661
ADV-2010-1552
http://www.vupen.com/english/advisories/2010/1552
DSA-2019
http://www.debian.org/security/2010/dsa-2019
MDVSA-2010:121
http://www.mandriva.com/security/advisories?name=MDVSA-2010:121
RHSA-2010:0140
http://www.redhat.com/support/errata/RHSA-2010-0140.html
SUSE-SR:2010:009
http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00002.html
SUSE-SR:2010:012
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html
SUSE-SR:2010:013
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
http://ftp.gnome.org/pub/GNOME/sources/pango/1.27/pango-1.27.1.tar.bz2
https://bugzilla.redhat.com/show_bug.cgi?id=555831
oval:org.mitre.oval:def:9417
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9417
Common Vulnerability Exposure (CVE) ID: CVE-2011-0020
1024994
http://www.securitytracker.com/id?1024994
42934
http://secunia.com/advisories/42934
43100
http://secunia.com/advisories/43100
45842
http://www.securityfocus.com/bid/45842
70596
http://osvdb.org/70596
ADV-2011-0186
http://www.vupen.com/english/advisories/2011/0186
ADV-2011-0238
http://www.vupen.com/english/advisories/2011/0238
RHSA-2011:0180
http://www.redhat.com/support/errata/RHSA-2011-0180.html
SUSE-SR:2011:005
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html
[oss-security] 20110118 CVE request: heap corruption in libpango
http://openwall.com/lists/oss-security/2011/01/18/6
[oss-security] 20110120 Re: CVE request: heap corruption in libpango
http://openwall.com/lists/oss-security/2011/01/20/2
https://bugs.launchpad.net/ubuntu/+source/pango1.0/+bug/696616
https://bugzilla.gnome.org/show_bug.cgi?id=639882
https://bugzilla.redhat.com/show_bug.cgi?id=671122
pango-pango-bo(64832)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64832
Common Vulnerability Exposure (CVE) ID: CVE-2011-0064
BugTraq ID: 46632
http://www.securityfocus.com/bid/46632
Debian Security Information: DSA-2178 (Google Search)
http://www.debian.org/security/2011/dsa-2178
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056065.html
http://www.mandriva.com/security/advisories?name=MDVSA-2011:040
http://www.redhat.com/support/errata/RHSA-2011-0309.html
http://securitytracker.com/id?1025145
http://secunia.com/advisories/43559
http://secunia.com/advisories/43572
http://secunia.com/advisories/43578
http://secunia.com/advisories/43800
SuSE Security Announcement: SUSE-SR:2011:005 (Google Search)
http://www.ubuntu.com/usn/USN-1082-1
http://www.vupen.com/english/advisories/2011/0543
http://www.vupen.com/english/advisories/2011/0555
http://www.vupen.com/english/advisories/2011/0558
http://www.vupen.com/english/advisories/2011/0584
http://www.vupen.com/english/advisories/2011/0683
XForce ISS Database: pango-hbbufferensure-bo(65770)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65770
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.