MGASA-2019-0235 - Updated pango packages fix security vulnerability

Publication date: 31 Aug 2019
URL: https://advisories.mageia.org/MGASA-2019-0235.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-1010238

Updated pango package fixes security vulnerability:

It was discovered that pango was subject to a heap based buffer overflow
vulnerability which could be used to get code execution (CVE-2019-1010238).

References:
- https://bugs.mageia.org/show_bug.cgi?id=25288
- https://ubuntu.com/security/notices/USN-4081-1
- https://www.debian.org/security/2019/dsa-4496
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010238

SRPMS:
- 7/core/pango-1.43.0-3.1.mga7

Mageia 2019-0235: pango security update

Updated pango package fixes security vulnerability: It was discovered that pango was subject to a heap based buffer overflow vulnerability which could be used to get code executio...

Summary

Updated pango package fixes security vulnerability:
It was discovered that pango was subject to a heap based buffer overflow vulnerability which could be used to get code execution (CVE-2019-1010238).

References

- https://bugs.mageia.org/show_bug.cgi?id=25288

- https://ubuntu.com/security/notices/USN-4081-1

- https://www.debian.org/security/2019/dsa-4496

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010238

Resolution

MGASA-2019-0235 - Updated pango packages fix security vulnerability

SRPMS

- 7/core/pango-1.43.0-3.1.mga7

Severity
Publication date: 31 Aug 2019
URL: https://advisories.mageia.org/MGASA-2019-0235.html
Type: security
CVE: CVE-2019-1010238

Related News