Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 29 pango: 2019-155e34df5a Critical: Fix Heap Buffer Overflow

fedora
Calendar Grey August 30, 2019
Dist Fedora Esm H88
Important update released for pango to resolve heap overflow vulnerability in Fedora 29. Ensure your system is secured.
Security fix for CVE-2019-1010238

Summary

Pango is a library for laying out and rendering of text, with an emphasis

on internationalization. Pango can be used anywhere that text layout is needed,

though most of the work on Pango so far has been done in the context of the

GTK+ widget toolkit. Pango forms the core of text and font handling for GTK+.

Pango is designed to be modular; the core Pango layout engine can be used

with different font backends.

The integration of Pango with Cairo provides a complete solution with high

quality text handling and graphics rendering.

Security fix for CVE-2019-1010238

* Wed Aug 14 2019 Peng Wu - 1.42.4-3

- Fixes bidi crash

- Security fix for CVE-2019-1010238

* Fri Jan 18 2019 Peng Wu - 1.42.4-2

- Fixes crash in pango_fc_font_key_get_variations when key is null

[ 1 ] Bug #1737785 - CVE-2019-1010238 pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow

https://bugzilla.redhat.com/show_bug.cgi?id=1737785

su -c 'dnf upgrade --advisory FEDORA-2019-155e34df5a' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 29
Version: 1.42.4
Release: 3.fc29
URL:
Summary: System for layout and rendering of internationalized text

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here