Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 24 articles for you...
98

RedHat: RHSA-2019-3234 Important: Pango Heap Overflow Fix

An update for pango is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pango security update Advisory ID: RHSA-2019:3234-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:3234 Issue date: 2019-10-29 CVE Names: CVE-2019-1010238 ==================================================================== 1. Summary: An update for pango is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6) - x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.6) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.6) - ppc64, ppc64le, s390x, x86_64 3. Description: Pango is a library for laying out and rendering of text, with an emphasis on internationalization. Pango forms the core of text and font handling for the GTK+ widget toolkit. Security Fix(es): * pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow (CVE-2019-1010238) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply thisupdate, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1737785 - CVE-2019-1010238 pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6): Source: pango-1.42.4-3.el7_6.src.rpm x86_64: pango-1.42.4-3.el7_6.i686.rpm pango-1.42.4-3.el7_6.x86_64.rpm pango-debuginfo-1.42.4-3.el7_6.i686.rpm pango-debuginfo-1.42.4-3.el7_6.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6): x86_64: pango-debuginfo-1.42.4-3.el7_6.i686.rpm pango-debuginfo-1.42.4-3.el7_6.x86_64.rpm pango-devel-1.42.4-3.el7_6.i686.rpm pango-devel-1.42.4-3.el7_6.x86_64.rpm pango-tests-1.42.4-3.el7_6.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.6): Source: pango-1.42.4-3.el7_6.src.rpm ppc64: pango-1.42.4-3.el7_6.ppc.rpm pango-1.42.4-3.el7_6.ppc64.rpm pango-debuginfo-1.42.4-3.el7_6.ppc.rpm pango-debuginfo-1.42.4-3.el7_6.ppc64.rpm pango-devel-1.42.4-3.el7_6.ppc.rpm pango-devel-1.42.4-3.el7_6.ppc64.rpm ppc64le: pango-1.42.4-3.el7_6.ppc64le.rpm pango-debuginfo-1.42.4-3.el7_6.ppc64le.rpm pango-devel-1.42.4-3.el7_6.ppc64le.rpm s390x: pango-1.42.4-3.el7_6.s390.rpm pango-1.42.4-3.el7_6.s390x.rpm pango-debuginfo-1.42.4-3.el7_6.s390.rpm pango-debuginfo-1.42.4-3.el7_6.s390x.rpm pango-devel-1.42.4-3.el7_6.s390.rpm pango-devel-1.42.4-3.el7_6.s390x.rpm x86_64: pango-1.42.4-3.el7_6.i686.rpm pango-1.42.4-3.el7_6.x86_64.rpm pango-debuginfo-1.42.4-3.el7_6.i686.rpm pango-debuginfo-1.42.4-3.el7_6.x86_64.rpm pango-devel-1.42.4-3.el7_6.i686.rpm pango-devel-1.42.4-3.el7_6.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v.7.6): ppc64: pango-debuginfo-1.42.4-3.el7_6.ppc64.rpm pango-tests-1.42.4-3.el7_6.ppc64.rpm ppc64le: pango-debuginfo-1.42.4-3.el7_6.ppc64le.rpm pango-tests-1.42.4-3.el7_6.ppc64le.rpm s390x: pango-debuginfo-1.42.4-3.el7_6.s390x.rpm pango-tests-1.42.4-3.el7_6.s390x.rpm x86_64: pango-debuginfo-1.42.4-3.el7_6.x86_64.rpm pango-tests-1.42.4-3.el7_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-1010238 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE-----Version: GnuPG v1 iQIVAwUBXbhG1tzjgjWX9erEAQgK5g//QMbE03tLvVK2lJo0AJMEkKoCz/xPiOw+ AjjT6jBKWtdX7qZZhMmZ73jZze4JJdMyDdSr3txGBMRCxW7Pw8kRSSbhI1E7qjDk a97JOcVhWcAir3ahjjz34mrgxZXCBrgAUZNmGGTdPjkFrEB6lwy4n17ZiVicmDPo AqxbrBpoxeDALCWER6o2vFnYibElwojjkoVeIAM6LJS4eaT11Fc+YCX41BkJkhAh vprKjfNVa3xxOejPaBMQXnL9+pqwhEiB897utmEUOskOc+T85sf1TwrIm+vtacLt TAMw+bWV+tq9ncSGrcV0h7hSX61KCyWrrj4PrPWi0YNGonQtRKwm+Abxiaav3SzS gonBCAlOkUby70ggfoUMnaXUJjlUx/+DhHFOf6L4MLgYvTHPRGr2je0TWjXt4pdP +0nfWcxsWJjQtLkoIewojalIJoDdv5tQVJ/KC0tVZQChU2kK/Vj/MMw1J3CRB2+n xdM+dGCsB0no2wiaOVp+AJe5WupYxw4qVLmhQCKk9KWXYU//pd/SFewZrn0fqd94 AnuC99yMjI5LaCElhC/BTSt44Mj7K6PVsR6F+WKjg80m3OiVv1AMTEBROBOz9zp9 h0Cf/nVxMVuSyv8EhaaTL7Vl8+V7x+3IAPDmCcYKvN/YL7T4WvJ19K8H6EPnrzo8 JkFyj6neoMQ=5l5F -----END PGP SIGNATURE-------RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical: pango security patch for Red Hat Enterprise Linux 7.6. Significant implications evaluated by Red Hat's product security team.. Pango Update, Red Hat Security, Linux Security Advisory, Extended Support, Heap Overflow Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 29, 2019 Important Red Hat
199

CentOS 7: CESA-2019-2571 Important Update for Pango Security

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2571. CentOS Errata and Security Advisory 2019:2571 Important Upstream details at : https://access.redhat.com/errata/RHSA-2019:2571 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: b61eb6385f406b7210f8c9095540a28e97eaf9e94c68fb00cd72ac4ea4b5c5a6 pango-1.42.4-4.el7_7.i686.rpm b45e82bace13bf493ae1ba13a73d110af4b4205b34c3af666e295b2154fa7621 pango-1.42.4-4.el7_7.x86_64.rpm 2d1f72e2f9fec0f35754e6f9645d434a96a64574208a4c0e522ba1845d2b9a34 pango-devel-1.42.4-4.el7_7.i686.rpm 9a461610eb324af42a252eb534b65ff00eda503d49c04347a36db6d0615da977 pango-devel-1.42.4-4.el7_7.x86_64.rpm 28114a9dd79fe28cea22af9f0eedab5f5102a034c5d8a6c2e8936d6a5ac72ef1 pango-tests-1.42.4-4.el7_7.x86_64.rpm Source: 68c7214d141db5f39348e4cf414652ccaa20a68f57e5136afddc1e64555c2c63 pango-1.42.4-4.el7_7.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #This email address is being protected from spambots. You need JavaScript enabled to view it. Twitter: @JohnnyCentOS _______________________________________________ CentOS-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . CentOS Errata and Security Advisory CESA-2020-4789 features significant enhancements regarding Pango. Discover the most recent protective protocols.. CentOS 7 Security Update, Pango Update, Security Advisory 2019, CentOS Errata. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 18, 2019 Important CentOS
203

Mageia: 2019-0235 Moderate: Pango Heap Overflow Threat Mitigated

Updated pango package fixes security vulnerability: It was discovered that pango was subject to a heap based buffer overflow vulnerability which could be used to get code execution (CVE-2019-1010238). . MGASA-2019-0235 - Updated pango packages fix security vulnerability Publication date: 31 Aug 2019 URL: https://advisories.mageia.org/MGASA-2019-0235.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-1010238 Updated pango package fixes security vulnerability: It was discovered that pango was subject to a heap based buffer overflow vulnerability which could be used to get code execution (CVE-2019-1010238). References: - https://bugs.mageia.org/show_bug.cgi?id=25288 - https://ubuntu.com/security/notices/USN-4081-1 - https://lists.debian.org/debian-security-announce/2019/msg00144.html - https://www.cve.org/CVERecord?id=CVE-2019-1010238 SRPMS: - 7/core/pango-1.43.0-3.1.mga7 . Revised pango updates address critical memory corruption vulnerabilities impacting Mageia platforms.. pango, security advisory, buffer overflow, Mageia update. . LinuxSecurity.com Team

Calendar%202 Aug 31, 2019 Mageia
89

Fedora 29 pango: 2019-155e34df5a Critical: Fix Heap Buffer Overflow

Security fix for CVE-2019-1010238. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-155e34df5a 2019-08-31 01:38:23.171354 --------------------------------------------------------------------------------Name : pango Product : Fedora 29 Version : 1.42.4 Release : 3.fc29 URL : Summary : System for layout and rendering of internationalized text Description : Pango is a library for laying out and rendering of text, with an emphasis on internationalization. Pango can be used anywhere that text layout is needed, though most of the work on Pango so far has been done in the context of the GTK+ widget toolkit. Pango forms the core of text and font handling for GTK+. Pango is designed to be modular; the core Pango layout engine can be used with different font backends. The integration of Pango with Cairo provides a complete solution with high quality text handling and graphics rendering. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-1010238 --------------------------------------------------------------------------------ChangeLog: * Wed Aug 14 2019 Peng Wu - 1.42.4-3 - Fixes bidi crash - Security fix for CVE-2019-1010238 * Fri Jan 18 2019 Peng Wu - 1.42.4-2 - Fixes crash in pango_fc_font_key_get_variations when key is null --------------------------------------------------------------------------------References: [ 1 ] Bug #1737785 - CVE-2019-1010238 pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=1737785 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-155e34df5a' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Important update released for pango to resolve heap overflow vulnerability in Fedora 29. Ensure your system is secured.. Fedora Security Advisory, Pango Update, Buffer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 30, 2019 Critical Fedora
98

Red Hat Enterprise Linux 8 RHSA-2019-2582-01 Urgent: Pango Buffer Overflow

An update for pango is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pango security update Advisory ID: RHSA-2019:2582-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:2582 Issue date: 2019-08-29 CVE Names: CVE-2019-1010238 ==================================================================== 1. Summary: An update for pango is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: Pango is a library for laying out and rendering of text, with an emphasis on internationalization. Pango forms the core of text and font handling for the GTK+ widget toolkit. Security Fix(es): * pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow (CVE-2019-1010238) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1737785 - CVE-2019-1010238 pango: pango_log2vis_get_embedding_levels() heap-basedbuffer overflow 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: pango-1.42.4-5.el8_0.src.rpm aarch64: pango-1.42.4-5.el8_0.aarch64.rpm pango-debuginfo-1.42.4-5.el8_0.aarch64.rpm pango-debugsource-1.42.4-5.el8_0.aarch64.rpm pango-devel-1.42.4-5.el8_0.aarch64.rpm pango-tests-debuginfo-1.42.4-5.el8_0.aarch64.rpm ppc64le: pango-1.42.4-5.el8_0.ppc64le.rpm pango-debuginfo-1.42.4-5.el8_0.ppc64le.rpm pango-debugsource-1.42.4-5.el8_0.ppc64le.rpm pango-devel-1.42.4-5.el8_0.ppc64le.rpm pango-tests-debuginfo-1.42.4-5.el8_0.ppc64le.rpm s390x: pango-1.42.4-5.el8_0.s390x.rpm pango-debuginfo-1.42.4-5.el8_0.s390x.rpm pango-debugsource-1.42.4-5.el8_0.s390x.rpm pango-devel-1.42.4-5.el8_0.s390x.rpm pango-tests-debuginfo-1.42.4-5.el8_0.s390x.rpm x86_64: pango-1.42.4-5.el8_0.i686.rpm pango-1.42.4-5.el8_0.x86_64.rpm pango-debuginfo-1.42.4-5.el8_0.i686.rpm pango-debuginfo-1.42.4-5.el8_0.x86_64.rpm pango-debugsource-1.42.4-5.el8_0.i686.rpm pango-debugsource-1.42.4-5.el8_0.x86_64.rpm pango-devel-1.42.4-5.el8_0.i686.rpm pango-devel-1.42.4-5.el8_0.x86_64.rpm pango-tests-debuginfo-1.42.4-5.el8_0.i686.rpm pango-tests-debuginfo-1.42.4-5.el8_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-1010238 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXWd2GNzjgjWX9erEAQgU8Q/+PxNnU5BrnuSnKQXqgf1MhHidMr79cfMw qHOnYlU+6KecKHLrwQ0XHKxjB6a/oeSjBF8YPXL/wNgP1QZhAyMjxENN58Vcsh2p XFVjdUMplDrmNtn1DKk6RrtEmIQXHpCEg2j81K2ILWgEsBshsLn1aFjHKjdY6zJb fhGMumEzv7se8HzIjLBzrEbTEVVAVkxMxqkVGQcn7M/BabycM8Hv1GFF14rjiX+j J1hxJ5USO7t8aX+Nvu1EV2DVVSvM6B2z97I1Enh/rhNzXt86fydM6+5/SCk8tWsU 2YQKOaGh59T+T2nGoMGdU9wRQixnz1RROZ3fwgKLb4kEsZQnxsK6RwCsD133Sxpy 29mPwN+FMRkaf/GjL4o3p9kFKcSuFg/WW1AM4+WmGzsvv7qK4Twv5Mx+BCzuaFs1 1nrNDKn6QO4JLbvVIsJXM0J0I266b0HdwRbvXIdRklBEVn7082F7c+XX2NRIPXku BuTinvG3MpxVQUVPrsgpgSGfjQPUMnTX8CCZIIfMSEOdvQiz8QI8DbitqBIiMJlc 1VrEX70AqYGAUDhRUnkLQzuyMnFXx5ao+S6vDw9RoT5hbhiZxe0zdHt1cLUIT+8e i2nqGb+r+FRpwFFSjt5kp3uoh7gNQ6SwcAyuHJl3ojYVC5ouJe98WSe3g5AdQEJk NYbWcMNawuQ=s39G -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial pango security patch for Red Hat Enterprise Linux tackles a severe memory overflow vulnerability.. Red Hat Enterprise, pango security, buffer overflow fix, Linux security update, software patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 29, 2019 Important Red Hat
200

Scientific Linux SL7: SLSA-2019-2571-1 Critical: pango Heap Overflow

pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow (CVE-2019-1010238) SL7 x86_64 pango-1.42.4-4.el7_7.i686.rpm pango-1.42.4-4.el7_7.x86_64.rpm pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-devel-1.42.4-4.el7_7.i686.rpm pango-devel-1.42.4-4.el7_7.x86_64.rpm pango-tests-1.42.4-4.el7_7.x86_64.rpm - Scien [More...]. Synopsis: Important: pango security update Advisory ID: SLSA-2019:2571-1 Issue Date: 2019-08-28 CVE Numbers: CVE-2019-1010238 -- Security Fix(es): * pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow (CVE-2019-1010238) -- SL7 x86_64 pango-1.42.4-4.el7_7.i686.rpm pango-1.42.4-4.el7_7.x86_64.rpm pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-devel-1.42.4-4.el7_7.i686.rpm pango-devel-1.42.4-4.el7_7.x86_64.rpm pango-tests-1.42.4-4.el7_7.x86_64.rpm - Scientific Linux Development Team . Important pango security patch for Scientific Linux SL7 resolving heap overflow vulnerabilities. Discover the specifics of this update immediately.. pango security, buffer overflow, Scientific Linux, SL7 update, security patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 28, 2019 Critical Scientific Linux
98

RedHat: RHSA-2019-2571-01 Important: Pango Heap Overflow Security Issue

An update for pango is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pango security update Advisory ID: RHSA-2019:2571-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:2571 Issue date: 2019-08-28 CVE Names: CVE-2019-1010238 ==================================================================== 1. Summary: An update for pango is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: Pango is a library for laying out and rendering of text, with an emphasis on internationalization. Pango forms the core of text and font handling for the GTK+ widget toolkit. Security Fix(es): * pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow (CVE-2019-1010238) For more details about the security issue(s), including the impact, aCVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1737785 - CVE-2019-1010238 pango: pango_log2vis_get_embedding_levels() heap-based buffer overflow 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: pango-1.42.4-4.el7_7.src.rpm x86_64: pango-1.42.4-4.el7_7.i686.rpm pango-1.42.4-4.el7_7.x86_64.rpm pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-devel-1.42.4-4.el7_7.i686.rpm pango-devel-1.42.4-4.el7_7.x86_64.rpm pango-tests-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: pango-1.42.4-4.el7_7.src.rpm x86_64: pango-1.42.4-4.el7_7.i686.rpm pango-1.42.4-4.el7_7.x86_64.rpm pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-devel-1.42.4-4.el7_7.i686.rpm pango-devel-1.42.4-4.el7_7.x86_64.rpm pango-tests-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: pango-1.42.4-4.el7_7.src.rpm ppc64: pango-1.42.4-4.el7_7.ppc.rpm pango-1.42.4-4.el7_7.ppc64.rpm pango-debuginfo-1.42.4-4.el7_7.ppc.rpm pango-debuginfo-1.42.4-4.el7_7.ppc64.rpm pango-devel-1.42.4-4.el7_7.ppc.rpm pango-devel-1.42.4-4.el7_7.ppc64.rpm ppc64le: pango-1.42.4-4.el7_7.ppc64le.rpm pango-debuginfo-1.42.4-4.el7_7.ppc64le.rpm pango-devel-1.42.4-4.el7_7.ppc64le.rpm s390x: pango-1.42.4-4.el7_7.s390.rpm pango-1.42.4-4.el7_7.s390x.rpm pango-debuginfo-1.42.4-4.el7_7.s390.rpm pango-debuginfo-1.42.4-4.el7_7.s390x.rpm pango-devel-1.42.4-4.el7_7.s390.rpm pango-devel-1.42.4-4.el7_7.s390x.rpm x86_64: pango-1.42.4-4.el7_7.i686.rpm pango-1.42.4-4.el7_7.x86_64.rpm pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-devel-1.42.4-4.el7_7.i686.rpm pango-devel-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64: pango-debuginfo-1.42.4-4.el7_7.ppc64.rpm pango-tests-1.42.4-4.el7_7.ppc64.rpm ppc64le: pango-debuginfo-1.42.4-4.el7_7.ppc64le.rpm pango-tests-1.42.4-4.el7_7.ppc64le.rpm s390x: pango-debuginfo-1.42.4-4.el7_7.s390x.rpm pango-tests-1.42.4-4.el7_7.s390x.rpm x86_64: pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-tests-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: pango-1.42.4-4.el7_7.src.rpm x86_64: pango-1.42.4-4.el7_7.i686.rpm pango-1.42.4-4.el7_7.x86_64.rpm pango-debuginfo-1.42.4-4.el7_7.i686.rpm pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-devel-1.42.4-4.el7_7.i686.rpm pango-devel-1.42.4-4.el7_7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: pango-debuginfo-1.42.4-4.el7_7.x86_64.rpm pango-tests-1.42.4-4.el7_7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-1010238 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat securitycontact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXWazjtzjgjWX9erEAQhMOhAAkmAhRyaZqMVJw/iiUYlu1qECUAhRaT5k mv1TBBT/wiaeSmzoGZ2q1v/qspnCvB+PaRRlF1aBvUeQWxN8TG3A0vJqo+cuRBrL JNKg/RdHzVSrtXRaLXtbPWdJp9ve0HVBle4c/K4wL3r95ykIpQN8d//7VWgvZZ+p GgXh9p9D9lZMY/GwIQjmiylMHvmOQXb1442eMHfFdQ4dRKuuz+g+BLLf9ptCFYuZ dCuNDO0V4C6+lqCWuTTO/eWvu/JSpq6CtQME+KXrHH9Irjcs4WXu3aC26yChhSyA itqkAdF+ntA0cZPAP+BCmOv2WOtPUz/WxIWdb/i1B5GnnAlemHJz+aFTANKMdRJn Sr+4GWsafXULtjUYt1/J0lipaX/dJ2rGCDRjRLSPSz1uJJf9CX+m4L+5EXZSV4OO 5EIzTeYAcY2ncdrpbW4mNzXtPtYsy6m8Ght+Wt3GCOFukWKPHvtaZDCXpRKzuZD/ rdMeoO5e745oHQ+abX7w7h47GYmfzBqeKh6J/rclkOE5hpRFVG5WsVyLIlYe9+cC Mv/S70NRT78VUgffmsTpS4fipnEtWrEXn8/G+z6sPz6ZDcryJgmJ8TvwnLVz4hm/ 2tJ/E2c23t9tUkrRmxAzA6aec2mPXLFE5c2CHJosm8XShdzDrI1E4kQjGqOB6CcL LI1VPC3/HSk=Ti1Y -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Pango vulnerability patch for Red Hat Enterprise Linux addresses a critical memory management flaw. Ensure you upgrade promptly to protect your environment.. Pango Security Update, Red Hat Advisory, Heap Overflow Fix, Security Enhancement. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 28, 2019 Important Red Hat
89

Fedora 30 FEDORA-2019-547be4a683 Critical: Pango Heap Overflow

Security fix for CVE-2019-1010238. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-547be4a683 2019-08-21 01:04:08.842400 --------------------------------------------------------------------------------Name : pango Product : Fedora 30 Version : 1.43.0 Release : 4.fc30 URL : Summary : System for layout and rendering of internationalized text Description : Pango is a library for laying out and rendering of text, with an emphasis on internationalization. Pango can be used anywhere that text layout is needed, though most of the work on Pango so far has been done in the context of the GTK+ widget toolkit. Pango forms the core of text and font handling for GTK+. Pango is designed to be modular; the core Pango layout engine can be used with different font backends. The integration of Pango with Cairo provides a complete solution with high quality text handling and graphics rendering. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-1010238 --------------------------------------------------------------------------------ChangeLog: * Wed Aug 14 2019 Peng Wu - 1.43.0-4 - Fixes bidi crash - Security fix for CVE-2019-1010238 --------------------------------------------------------------------------------References: [ 1 ] Bug #1737785 - CVE-2019-1010238 pango: pango_log2vis_get_embedding_levels() heap based buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=1737785 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-547be4a683' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Alliance 45 tackles an important vulnerability in libgtk, fixing buffer overrun problems to strengthen core security.. Fedora Security Advisory, Pango Heap Overflow Fix, Critical Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 20, 2019 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200