Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Ubuntu 19.04: USN-4081-1 Critical: Pango Arbitrary Code Execution

Ubuntu Large Esm H500
Pango could be made to execute arbitrary code if it received a specially crafted input.
=========================================================================Ubuntu Security Notice USN-4081-1
July 31, 2019

pango1.0 vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.04

Summary:

Pango could be made to execute arbitrary code if it received a specially
crafted input.

Software Description:
- pango1.0: Layout and rendering of internationalized text - gir bindings

Details:

It was discovered that Pango incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
  gir1.2-pango-1.0                1.42.4-6ubuntu0.1
  libpango-1.0-0                  1.42.4-6ubuntu0.1
  libpango1.0-0                   1.42.4-6ubuntu0.1

After a standard system update you need to restart your session to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4081-1
  CVE-2019-1010238

Package Information:
  https://launchpad.net/ubuntu/+source/pango1.0/1.42.4-6ubuntu0.1

Ubuntu 19.04: USN-4081-1 Critical: Pango Arbitrary Code Execution

ubuntu
Calendar Grey July 31, 2019
Dist Ubuntu Esm H88
The latest Ubuntu Security Alert USN-4081-1 details a vulnerability in Pango that permits the execution of arbitrary code when fed with specifically designed input.
Pango could be made to execute arbitrary code if it received a specially crafted input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: gir1.2-pango-1.0 1.42.4-6ubuntu0.1 libpango-1.0-0 1.42.4-6ubuntu0.1 libpango1.0-0 1.42.4-6ubuntu0.1 After a standard system update you need to restart your session to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4081-1

CVE-2019-1010238

Severity
critical
Lowest
Low
Medium
High
Critical

July 31, 2019

Package Information

https://launchpad.net/ubuntu/+source/pango1.0/1.42.4-6ubuntu0.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here