Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update for pango is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pango security update Advisory ID: RHSA-2019:3234-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:3234 Issue date: 2019-10-29 CVE Names: CVE-2019-1010238 ==================================================================== 1. Summary: An update for pango is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6) - x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.6) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.6) - ppc64, ppc64le, s390x, x86_64 3. Description: Pango is a library for laying out and rendering of text, with an emphasis on internationalization. Pango forms the core of text and font handling for the GTK+ widget toolkit. Security Fix(es): * pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow (CVE-2019-1010238) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply thisupdate, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1737785 - CVE-2019-1010238 pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6): Source: pango-1.42.4-3.el7_6.src.rpm x86_64: pango-1.42.4-3.el7_6.i686.rpm pango-1.42.4-3.el7_6.x86_64.rpm pango-debuginfo-1.42.4-3.el7_6.i686.rpm pango-debuginfo-1.42.4-3.el7_6.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6): x86_64: pango-debuginfo-1.42.4-3.el7_6.i686.rpm pango-debuginfo-1.42.4-3.el7_6.x86_64.rpm pango-devel-1.42.4-3.el7_6.i686.rpm pango-devel-1.42.4-3.el7_6.x86_64.rpm pango-tests-1.42.4-3.el7_6.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.6): Source: pango-1.42.4-3.el7_6.src.rpm ppc64: pango-1.42.4-3.el7_6.ppc.rpm pango-1.42.4-3.el7_6.ppc64.rpm pango-debuginfo-1.42.4-3.el7_6.ppc.rpm pango-debuginfo-1.42.4-3.el7_6.ppc64.rpm pango-devel-1.42.4-3.el7_6.ppc.rpm pango-devel-1.42.4-3.el7_6.ppc64.rpm ppc64le: pango-1.42.4-3.el7_6.ppc64le.rpm pango-debuginfo-1.42.4-3.el7_6.ppc64le.rpm pango-devel-1.42.4-3.el7_6.ppc64le.rpm s390x: pango-1.42.4-3.el7_6.s390.rpm pango-1.42.4-3.el7_6.s390x.rpm pango-debuginfo-1.42.4-3.el7_6.s390.rpm pango-debuginfo-1.42.4-3.el7_6.s390x.rpm pango-devel-1.42.4-3.el7_6.s390.rpm pango-devel-1.42.4-3.el7_6.s390x.rpm x86_64: pango-1.42.4-3.el7_6.i686.rpm pango-1.42.4-3.el7_6.x86_64.rpm pango-debuginfo-1.42.4-3.el7_6.i686.rpm pango-debuginfo-1.42.4-3.el7_6.x86_64.rpm pango-devel-1.42.4-3.el7_6.i686.rpm pango-devel-1.42.4-3.el7_6.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v.7.6): ppc64: pango-debuginfo-1.42.4-3.el7_6.ppc64.rpm pango-tests-1.42.4-3.el7_6.ppc64.rpm ppc64le: pango-debuginfo-1.42.4-3.el7_6.ppc64le.rpm pango-tests-1.42.4-3.el7_6.ppc64le.rpm s390x: pango-debuginfo-1.42.4-3.el7_6.s390x.rpm pango-tests-1.42.4-3.el7_6.s390x.rpm x86_64: pango-debuginfo-1.42.4-3.el7_6.x86_64.rpm pango-tests-1.42.4-3.el7_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-1010238 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE-----Version: GnuPG v1 iQIVAwUBXbhG1tzjgjWX9erEAQgK5g//QMbE03tLvVK2lJo0AJMEkKoCz/xPiOw+ AjjT6jBKWtdX7qZZhMmZ73jZze4JJdMyDdSr3txGBMRCxW7Pw8kRSSbhI1E7qjDk a97JOcVhWcAir3ahjjz34mrgxZXCBrgAUZNmGGTdPjkFrEB6lwy4n17ZiVicmDPo AqxbrBpoxeDALCWER6o2vFnYibElwojjkoVeIAM6LJS4eaT11Fc+YCX41BkJkhAh vprKjfNVa3xxOejPaBMQXnL9+pqwhEiB897utmEUOskOc+T85sf1TwrIm+vtacLt TAMw+bWV+tq9ncSGrcV0h7hSX61KCyWrrj4PrPWi0YNGonQtRKwm+Abxiaav3SzS gonBCAlOkUby70ggfoUMnaXUJjlUx/+DhHFOf6L4MLgYvTHPRGr2je0TWjXt4pdP +0nfWcxsWJjQtLkoIewojalIJoDdv5tQVJ/KC0tVZQChU2kK/Vj/MMw1J3CRB2+n xdM+dGCsB0no2wiaOVp+AJe5WupYxw4qVLmhQCKk9KWXYU//pd/SFewZrn0fqd94 AnuC99yMjI5LaCElhC/BTSt44Mj7K6PVsR6F+WKjg80m3OiVv1AMTEBROBOz9zp9 h0Cf/nVxMVuSyv8EhaaTL7Vl8+V7x+3IAPDmCcYKvN/YL7T4WvJ19K8H6EPnrzo8 JkFyj6neoMQ=5l5F -----END PGP SIGNATURE-------RHSA-announce mailing list
Upstream details at : https://access.redhat.com/errata/RHSA-2019:2571. CentOS Errata and Security Advisory 2019:2571 Important Upstream details at : https://access.redhat.com/errata/RHSA-2019:2571 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: b61eb6385f406b7210f8c9095540a28e97eaf9e94c68fb00cd72ac4ea4b5c5a6 pango-1.42.4-4.el7_7.i686.rpm b45e82bace13bf493ae1ba13a73d110af4b4205b34c3af666e295b2154fa7621 pango-1.42.4-4.el7_7.x86_64.rpm 2d1f72e2f9fec0f35754e6f9645d434a96a64574208a4c0e522ba1845d2b9a34 pango-devel-1.42.4-4.el7_7.i686.rpm 9a461610eb324af42a252eb534b65ff00eda503d49c04347a36db6d0615da977 pango-devel-1.42.4-4.el7_7.x86_64.rpm 28114a9dd79fe28cea22af9f0eedab5f5102a034c5d8a6c2e8936d6a5ac72ef1 pango-tests-1.42.4-4.el7_7.x86_64.rpm Source: 68c7214d141db5f39348e4cf414652ccaa20a68f57e5136afddc1e64555c2c63 pango-1.42.4-4.el7_7.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
Updated pango package fixes security vulnerability: It was discovered that pango was subject to a heap based buffer overflow vulnerability which could be used to get code execution (CVE-2019-1010238). . MGASA-2019-0235 - Updated pango packages fix security vulnerability Publication date: 31 Aug 2019 URL: https://advisories.mageia.org/MGASA-2019-0235.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-1010238 Updated pango package fixes security vulnerability: It was discovered that pango was subject to a heap based buffer overflow vulnerability which could be used to get code execution (CVE-2019-1010238). References: - https://bugs.mageia.org/show_bug.cgi?id=25288 - https://ubuntu.com/security/notices/USN-4081-1 - https://lists.debian.org/debian-security-announce/2019/msg00144.html - https://www.cve.org/CVERecord?id=CVE-2019-1010238 SRPMS: - 7/core/pango-1.43.0-3.1.mga7 . Revised pango updates address critical memory corruption vulnerabilities impacting Mageia platforms.. pango, security advisory, buffer overflow, Mageia update. . LinuxSecurity.com Team
Security fix for CVE-2019-1010238. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-155e34df5a 2019-08-31 01:38:23.171354 --------------------------------------------------------------------------------Name : pango Product : Fedora 29 Version : 1.42.4 Release : 3.fc29 URL : Summary : System for layout and rendering of internationalized text Description : Pango is a library for laying out and rendering of text, with an emphasis on internationalization. Pango can be used anywhere that text layout is needed, though most of the work on Pango so far has been done in the context of the GTK+ widget toolkit. Pango forms the core of text and font handling for GTK+. Pango is designed to be modular; the core Pango layout engine can be used with different font backends. The integration of Pango with Cairo provides a complete solution with high quality text handling and graphics rendering. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-1010238 --------------------------------------------------------------------------------ChangeLog: * Wed Aug 14 2019 Peng Wu - 1.42.4-3 - Fixes bidi crash - Security fix for CVE-2019-1010238 * Fri Jan 18 2019 Peng Wu - 1.42.4-2 - Fixes crash in pango_fc_font_key_get_variations when key is null --------------------------------------------------------------------------------References: [ 1 ] Bug #1737785 - CVE-2019-1010238 pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=1737785 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-155e34df5a' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update for pango is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pango security update Advisory ID: RHSA-2019:2582-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:2582 Issue date: 2019-08-29 CVE Names: CVE-2019-1010238 ==================================================================== 1. Summary: An update for pango is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: Pango is a library for laying out and rendering of text, with an emphasis on internationalization. Pango forms the core of text and font handling for the GTK+ widget toolkit. Security Fix(es): * pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow (CVE-2019-1010238) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1737785 - CVE-2019-1010238 pango: pango_log2vis_get_embedding_levels() heap-basedbuffer overflow 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: pango-1.42.4-5.el8_0.src.rpm aarch64: pango-1.42.4-5.el8_0.aarch64.rpm pango-debuginfo-1.42.4-5.el8_0.aarch64.rpm pango-debugsource-1.42.4-5.el8_0.aarch64.rpm pango-devel-1.42.4-5.el8_0.aarch64.rpm pango-tests-debuginfo-1.42.4-5.el8_0.aarch64.rpm ppc64le: pango-1.42.4-5.el8_0.ppc64le.rpm pango-debuginfo-1.42.4-5.el8_0.ppc64le.rpm pango-debugsource-1.42.4-5.el8_0.ppc64le.rpm pango-devel-1.42.4-5.el8_0.ppc64le.rpm pango-tests-debuginfo-1.42.4-5.el8_0.ppc64le.rpm s390x: pango-1.42.4-5.el8_0.s390x.rpm pango-debuginfo-1.42.4-5.el8_0.s390x.rpm pango-debugsource-1.42.4-5.el8_0.s390x.rpm pango-devel-1.42.4-5.el8_0.s390x.rpm pango-tests-debuginfo-1.42.4-5.el8_0.s390x.rpm x86_64: pango-1.42.4-5.el8_0.i686.rpm pango-1.42.4-5.el8_0.x86_64.rpm pango-debuginfo-1.42.4-5.el8_0.i686.rpm pango-debuginfo-1.42.4-5.el8_0.x86_64.rpm pango-debugsource-1.42.4-5.el8_0.i686.rpm pango-debugsource-1.42.4-5.el8_0.x86_64.rpm pango-devel-1.42.4-5.el8_0.i686.rpm pango-devel-1.42.4-5.el8_0.x86_64.rpm pango-tests-debuginfo-1.42.4-5.el8_0.i686.rpm pango-tests-debuginfo-1.42.4-5.el8_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-1010238 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXWd2GNzjgjWX9erEAQgU8Q/+PxNnU5BrnuSnKQXqgf1MhHidMr79cfMw qHOnYlU+6KecKHLrwQ0XHKxjB6a/oeSjBF8YPXL/wNgP1QZhAyMjxENN58Vcsh2p XFVjdUMplDrmNtn1DKk6RrtEmIQXHpCEg2j81K2ILWgEsBshsLn1aFjHKjdY6zJb fhGMumEzv7se8HzIjLBzrEbTEVVAVkxMxqkVGQcn7M/BabycM8Hv1GFF14rjiX+j J1hxJ5USO7t8aX+Nvu1EV2DVVSvM6B2z97I1Enh/rhNzXt86fydM6+5/SCk8tWsU 2YQKOaGh59T+T2nGoMGdU9wRQixnz1RROZ3fwgKLb4kEsZQnxsK6RwCsD133Sxpy 29mPwN+FMRkaf/GjL4o3p9kFKcSuFg/WW1AM4+WmGzsvv7qK4Twv5Mx+BCzuaFs1 1nrNDKn6QO4JLbvVIsJXM0J0I266b0HdwRbvXIdRklBEVn7082F7c+XX2NRIPXku BuTinvG3MpxVQUVPrsgpgSGfjQPUMnTX8CCZIIfMSEOdvQiz8QI8DbitqBIiMJlc 1VrEX70AqYGAUDhRUnkLQzuyMnFXx5ao+S6vDw9RoT5hbhiZxe0zdHt1cLUIT+8e i2nqGb+r+FRpwFFSjt5kp3uoh7gNQ6SwcAyuHJl3ojYVC5ouJe98WSe3g5AdQEJk NYbWcMNawuQ=s39G -----END PGP SIGNATURE----- -- RHSA-announce mailing list
pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow (CVE-2019-1010238) SL7 x86_64 pango-1.42.4-4.el7_7.i686.rpm pango-1.42.4-4.el7_7.x86_64.rpm pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-devel-1.42.4-4.el7_7.i686.rpm pango-devel-1.42.4-4.el7_7.x86_64.rpm pango-tests-1.42.4-4.el7_7.x86_64.rpm - Scien [More...]. Synopsis: Important: pango security update Advisory ID: SLSA-2019:2571-1 Issue Date: 2019-08-28 CVE Numbers: CVE-2019-1010238 -- Security Fix(es): * pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow (CVE-2019-1010238) -- SL7 x86_64 pango-1.42.4-4.el7_7.i686.rpm pango-1.42.4-4.el7_7.x86_64.rpm pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-devel-1.42.4-4.el7_7.i686.rpm pango-devel-1.42.4-4.el7_7.x86_64.rpm pango-tests-1.42.4-4.el7_7.x86_64.rpm - Scientific Linux Development Team . Important pango security patch for Scientific Linux SL7 resolving heap overflow vulnerabilities. Discover the specifics of this update immediately.. pango security, buffer overflow, Scientific Linux, SL7 update, security patch. . Severity: Critical. LinuxSecurity.com Team
An update for pango is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pango security update Advisory ID: RHSA-2019:2571-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:2571 Issue date: 2019-08-28 CVE Names: CVE-2019-1010238 ==================================================================== 1. Summary: An update for pango is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: Pango is a library for laying out and rendering of text, with an emphasis on internationalization. Pango forms the core of text and font handling for the GTK+ widget toolkit. Security Fix(es): * pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow (CVE-2019-1010238) For more details about the security issue(s), including the impact, aCVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1737785 - CVE-2019-1010238 pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: pango-1.42.4-4.el7_7.src.rpm x86_64: pango-1.42.4-4.el7_7.i686.rpm pango-1.42.4-4.el7_7.x86_64.rpm pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-devel-1.42.4-4.el7_7.i686.rpm pango-devel-1.42.4-4.el7_7.x86_64.rpm pango-tests-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: pango-1.42.4-4.el7_7.src.rpm x86_64: pango-1.42.4-4.el7_7.i686.rpm pango-1.42.4-4.el7_7.x86_64.rpm pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-devel-1.42.4-4.el7_7.i686.rpm pango-devel-1.42.4-4.el7_7.x86_64.rpm pango-tests-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: pango-1.42.4-4.el7_7.src.rpm ppc64: pango-1.42.4-4.el7_7.ppc.rpm pango-1.42.4-4.el7_7.ppc64.rpm pango-debuginfo-1.42.4-4.el7_7.ppc.rpm pango-debuginfo-1.42.4-4.el7_7.ppc64.rpm pango-devel-1.42.4-4.el7_7.ppc.rpm pango-devel-1.42.4-4.el7_7.ppc64.rpm ppc64le: pango-1.42.4-4.el7_7.ppc64le.rpm pango-debuginfo-1.42.4-4.el7_7.ppc64le.rpm pango-devel-1.42.4-4.el7_7.ppc64le.rpm s390x: pango-1.42.4-4.el7_7.s390.rpm pango-1.42.4-4.el7_7.s390x.rpm pango-debuginfo-1.42.4-4.el7_7.s390.rpm pango-debuginfo-1.42.4-4.el7_7.s390x.rpm pango-devel-1.42.4-4.el7_7.s390.rpm pango-devel-1.42.4-4.el7_7.s390x.rpm x86_64: pango-1.42.4-4.el7_7.i686.rpm pango-1.42.4-4.el7_7.x86_64.rpm pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-devel-1.42.4-4.el7_7.i686.rpm pango-devel-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64: pango-debuginfo-1.42.4-4.el7_7.ppc64.rpm pango-tests-1.42.4-4.el7_7.ppc64.rpm ppc64le: pango-debuginfo-1.42.4-4.el7_7.ppc64le.rpm pango-tests-1.42.4-4.el7_7.ppc64le.rpm s390x: pango-debuginfo-1.42.4-4.el7_7.s390x.rpm pango-tests-1.42.4-4.el7_7.s390x.rpm x86_64: pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-tests-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: pango-1.42.4-4.el7_7.src.rpm x86_64: pango-1.42.4-4.el7_7.i686.rpm pango-1.42.4-4.el7_7.x86_64.rpm pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-devel-1.42.4-4.el7_7.i686.rpm pango-devel-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-tests-1.42.4-4.el7_7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-1010238 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat securitycontact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXWazjtzjgjWX9erEAQhMOhAAkmAhRyaZqMVJw/iiUYlu1qECUAhRaT5k mv1TBBT/wiaeSmzoGZ2q1v/qspnCvB+PaRRlF1aBvUeQWxN8TG3A0vJqo+cuRBrL JNKg/RdHzVSrtXRaLXtbPWdJp9ve0HVBle4c/K4wL3r95ykIpQN8d//7VWgvZZ+p GgXh9p9D9lZMY/GwIQjmiylMHvmOQXb1442eMHfFdQ4dRKuuz+g+BLLf9ptCFYuZ dCuNDO0V4C6+lqCWuTTO/eWvu/JSpq6CtQME+KXrHH9Irjcs4WXu3aC26yChhSyA itqkAdF+ntA0cZPAP+BCmOv2WOtPUz/WxIWdb/i1B5GnnAlemHJz+aFTANKMdRJn Sr+4GWsafXULtjUYt1/J0lipaX/dJ2rGCDRjRLSPSz1uJJf9CX+m4L+5EXZSV4OO 5EIzTeYAcY2ncdrpbW4mNzXtPtYsy6m8Ght+Wt3GCOFukWKPHvtaZDCXpRKzuZD/ rdMeoO5e745oHQ+abX7w7h47GYmfzBqeKh6J/rclkOE5hpRFVG5WsVyLIlYe9+cC Mv/S70NRT78VUgffmsTpS4fipnEtWrEXn8/G+z6sPz6ZDcryJgmJ8TvwnLVz4hm/ 2tJ/E2c23t9tUkrRmxAzA6aec2mPXLFE5c2CHJosm8XShdzDrI1E4kQjGqOB6CcL LI1VPC3/HSk=Ti1Y -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Security fix for CVE-2019-1010238. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-547be4a683 2019-08-21 01:04:08.842400 --------------------------------------------------------------------------------Name : pango Product : Fedora 30 Version : 1.43.0 Release : 4.fc30 URL : Summary : System for layout and rendering of internationalized text Description : Pango is a library for laying out and rendering of text, with an emphasis on internationalization. Pango can be used anywhere that text layout is needed, though most of the work on Pango so far has been done in the context of the GTK+ widget toolkit. Pango forms the core of text and font handling for GTK+. Pango is designed to be modular; the core Pango layout engine can be used with different font backends. The integration of Pango with Cairo provides a complete solution with high quality text handling and graphics rendering. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-1010238 --------------------------------------------------------------------------------ChangeLog: * Wed Aug 14 2019 Peng Wu - 1.43.0-4 - Fixes bidi crash - Security fix for CVE-2019-1010238 --------------------------------------------------------------------------------References: [ 1 ] Bug #1737785 - CVE-2019-1010238 pango: pango_log2vis_get_embedding_levels() heap based buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=1737785 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-547be4a683' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.