Security fix for CVE-2018-15120. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-83116f8692 2018-09-13 17:05:57.362484 --------------------------------------------------------------------------------Name : pango Product : Fedora 27 Version : 1.40.14 Release : 3.fc27 URL : Summary : System for layout and rendering of internationalized text Description : Pango is a library for laying out and rendering of text, with an emphasis on internationalization. Pango can be used anywhere that text layout is needed, though most of the work on Pango so far has been done in the context of the GTK+ widget toolkit. Pango forms the core of text and font handling for GTK+. Pango is designed to be modular; the core Pango layout engine can be used with different font backends. The integration of Pango with Cairo provides a complete solution with high quality text handling and graphics rendering. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2018-15120 --------------------------------------------------------------------------------ChangeLog: * Fri Aug 31 2018 Peng Wu - 1.40.14-3 - Security fix for CVE-2018-15120 * Fri Aug 31 2018 Peng Wu - 1.40.14-2 - Fixes crash with invalid Unicode sequences * Sat Nov 18 2017 Leigh Scott - 1.40.14-1 - Update to 1.40.14 - Remove unused patch * Thu Nov 2 2017 Kalev Lember - 1.40.13-2 - Backport a patch to fix wrapping long filenames in Nautilus * Wed Nov 1 2017 Kalev Lember - 1.40.13-1 - Update to 1.40.13 --------------------------------------------------------------------------------References: [ 1 ] Bug #1613550 - CVE-2018-15120 pango: application crash triggered by unicode chars in pango-emoji.c https://bugzilla.redhat.com/show_bug.cgi?id=1613550 --------------------------------------------------------------------------------This update can be installedwith the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-83116f8692' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Updated pango and evolution28-pango packages that fix one security issue are now available for Red Hat Enterprise Linux 3, 4, and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: pango security update Advisory ID: RHSA-2010:0140-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2010:0140.html Issue date: 2010-03-15 CVE Names: CVE-2010-0421 ==================================================================== 1. Summary: Updated pango and evolution28-pango packages that fix one security issue are now available for Red Hat Enterprise Linux 3, 4, and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Description: Pango is a library used for the layout and rendering of internationalized text. An input sanitization flaw, leading to an array index error, was found in the way the Pango font rendering library synthesized the Glyph Definition (GDEF) table from a font's character map and the Unicode property database. If an attacker created aspecially-crafted font file and tricked a local, unsuspecting user into loading the font file in an application that uses the Pango font rendering library, it could cause that application to crash. (CVE-2010-0421) Users of pango and evolution28-pango are advised to upgrade to these updated packages, which contain a backported patch to resolve this issue. After installing this update, you must restart your system or restart your X session for this update to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 555831 - CVE-2010-0421 libpangoft2 segfaults on forged font files 6. Package List: Red Hat Enterprise Linux AS version 3: Source: i386: pango-1.2.5-10.i386.rpm pango-debuginfo-1.2.5-10.i386.rpm pango-devel-1.2.5-10.i386.rpm ia64: pango-1.2.5-10.i386.rpm pango-1.2.5-10.ia64.rpm pango-debuginfo-1.2.5-10.i386.rpm pango-debuginfo-1.2.5-10.ia64.rpm pango-devel-1.2.5-10.ia64.rpm ppc: pango-1.2.5-10.ppc.rpm pango-1.2.5-10.ppc64.rpm pango-debuginfo-1.2.5-10.ppc.rpm pango-debuginfo-1.2.5-10.ppc64.rpm pango-devel-1.2.5-10.ppc.rpm s390: pango-1.2.5-10.s390.rpm pango-debuginfo-1.2.5-10.s390.rpm pango-devel-1.2.5-10.s390.rpm s390x: pango-1.2.5-10.s390.rpm pango-1.2.5-10.s390x.rpm pango-debuginfo-1.2.5-10.s390.rpm pango-debuginfo-1.2.5-10.s390x.rpm pango-devel-1.2.5-10.s390x.rpm x86_64: pango-1.2.5-10.i386.rpm pango-1.2.5-10.x86_64.rpm pango-debuginfo-1.2.5-10.i386.rpm pango-debuginfo-1.2.5-10.x86_64.rpm pango-devel-1.2.5-10.x86_64.rpm Red Hat Desktop version 3: Source: i386: pango-1.2.5-10.i386.rpm pango-debuginfo-1.2.5-10.i386.rpm pango-devel-1.2.5-10.i386.rpm x86_64: pango-1.2.5-10.i386.rpm pango-1.2.5-10.x86_64.rpm pango-debuginfo-1.2.5-10.i386.rpm pango-debuginfo-1.2.5-10.x86_64.rpm pango-devel-1.2.5-10.x86_64.rpm Red Hat Enterprise Linux ESversion 3: Source: i386: pango-1.2.5-10.i386.rpm pango-debuginfo-1.2.5-10.i386.rpm pango-devel-1.2.5-10.i386.rpm ia64: pango-1.2.5-10.i386.rpm pango-1.2.5-10.ia64.rpm pango-debuginfo-1.2.5-10.i386.rpm pango-debuginfo-1.2.5-10.ia64.rpm pango-devel-1.2.5-10.ia64.rpm x86_64: pango-1.2.5-10.i386.rpm pango-1.2.5-10.x86_64.rpm pango-debuginfo-1.2.5-10.i386.rpm pango-debuginfo-1.2.5-10.x86_64.rpm pango-devel-1.2.5-10.x86_64.rpm Red Hat Enterprise Linux WS version 3: Source: i386: pango-1.2.5-10.i386.rpm pango-debuginfo-1.2.5-10.i386.rpm pango-devel-1.2.5-10.i386.rpm ia64: pango-1.2.5-10.i386.rpm pango-1.2.5-10.ia64.rpm pango-debuginfo-1.2.5-10.i386.rpm pango-debuginfo-1.2.5-10.ia64.rpm pango-devel-1.2.5-10.ia64.rpm x86_64: pango-1.2.5-10.i386.rpm pango-1.2.5-10.x86_64.rpm pango-debuginfo-1.2.5-10.i386.rpm pango-debuginfo-1.2.5-10.x86_64.rpm pango-devel-1.2.5-10.x86_64.rpm Red Hat Enterprise Linux AS version4: Source: i386: evolution28-pango-1.14.9-13.el4_8.i386.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.i386.rpm evolution28-pango-devel-1.14.9-13.el4_8.i386.rpm pango-1.6.0-16.el4_8.i386.rpm pango-debuginfo-1.6.0-16.el4_8.i386.rpm pango-devel-1.6.0-16.el4_8.i386.rpm ia64: evolution28-pango-1.14.9-13.el4_8.ia64.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.ia64.rpm evolution28-pango-devel-1.14.9-13.el4_8.ia64.rpm pango-1.6.0-16.el4_8.i386.rpm pango-1.6.0-16.el4_8.ia64.rpm pango-debuginfo-1.6.0-16.el4_8.i386.rpm pango-debuginfo-1.6.0-16.el4_8.ia64.rpm pango-devel-1.6.0-16.el4_8.ia64.rpm ppc: evolution28-pango-1.14.9-13.el4_8.ppc.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.ppc.rpm evolution28-pango-devel-1.14.9-13.el4_8.ppc.rpm pango-1.6.0-16.el4_8.ppc.rpm pango-1.6.0-16.el4_8.ppc64.rpm pango-debuginfo-1.6.0-16.el4_8.ppc.rpm pango-debuginfo-1.6.0-16.el4_8.ppc64.rpm pango-devel-1.6.0-16.el4_8.ppc.rpm s390: evolution28-pango-1.14.9-13.el4_8.s390.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.s390.rpm evolution28-pango-devel-1.14.9-13.el4_8.s390.rpm pango-1.6.0-16.el4_8.s390.rpm pango-debuginfo-1.6.0-16.el4_8.s390.rpm pango-devel-1.6.0-16.el4_8.s390.rpm s390x: evolution28-pango-1.14.9-13.el4_8.s390x.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.s390x.rpm evolution28-pango-devel-1.14.9-13.el4_8.s390x.rpm pango-1.6.0-16.el4_8.s390.rpm pango-1.6.0-16.el4_8.s390x.rpm pango-debuginfo-1.6.0-16.el4_8.s390.rpm pango-debuginfo-1.6.0-16.el4_8.s390x.rpm pango-devel-1.6.0-16.el4_8.s390x.rpm x86_64: evolution28-pango-1.14.9-13.el4_8.x86_64.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.x86_64.rpm evolution28-pango-devel-1.14.9-13.el4_8.x86_64.rpm pango-1.6.0-16.el4_8.i386.rpm pango-1.6.0-16.el4_8.x86_64.rpm pango-debuginfo-1.6.0-16.el4_8.i386.rpm pango-debuginfo-1.6.0-16.el4_8.x86_64.rpm pango-devel-1.6.0-16.el4_8.x86_64.rpm Red Hat Enterprise Linux Desktop version4: Source: i386: evolution28-pango-1.14.9-13.el4_8.i386.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.i386.rpm evolution28-pango-devel-1.14.9-13.el4_8.i386.rpm pango-1.6.0-16.el4_8.i386.rpm pango-debuginfo-1.6.0-16.el4_8.i386.rpm pango-devel-1.6.0-16.el4_8.i386.rpm x86_64: evolution28-pango-1.14.9-13.el4_8.x86_64.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.x86_64.rpm evolution28-pango-devel-1.14.9-13.el4_8.x86_64.rpm pango-1.6.0-16.el4_8.i386.rpm pango-1.6.0-16.el4_8.x86_64.rpm pango-debuginfo-1.6.0-16.el4_8.i386.rpm pango-debuginfo-1.6.0-16.el4_8.x86_64.rpm pango-devel-1.6.0-16.el4_8.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: evolution28-pango-1.14.9-13.el4_8.i386.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.i386.rpm evolution28-pango-devel-1.14.9-13.el4_8.i386.rpm pango-1.6.0-16.el4_8.i386.rpm pango-debuginfo-1.6.0-16.el4_8.i386.rpm pango-devel-1.6.0-16.el4_8.i386.rpm ia64: evolution28-pango-1.14.9-13.el4_8.ia64.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.ia64.rpm evolution28-pango-devel-1.14.9-13.el4_8.ia64.rpm pango-1.6.0-16.el4_8.i386.rpm pango-1.6.0-16.el4_8.ia64.rpm pango-debuginfo-1.6.0-16.el4_8.i386.rpm pango-debuginfo-1.6.0-16.el4_8.ia64.rpm pango-devel-1.6.0-16.el4_8.ia64.rpm x86_64: evolution28-pango-1.14.9-13.el4_8.x86_64.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.x86_64.rpm evolution28-pango-devel-1.14.9-13.el4_8.x86_64.rpm pango-1.6.0-16.el4_8.i386.rpm pango-1.6.0-16.el4_8.x86_64.rpm pango-debuginfo-1.6.0-16.el4_8.i386.rpm pango-debuginfo-1.6.0-16.el4_8.x86_64.rpm pango-devel-1.6.0-16.el4_8.x86_64.rpm Red Hat Enterprise Linux WS version4: Source: i386: evolution28-pango-1.14.9-13.el4_8.i386.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.i386.rpm evolution28-pango-devel-1.14.9-13.el4_8.i386.rpm pango-1.6.0-16.el4_8.i386.rpm pango-debuginfo-1.6.0-16.el4_8.i386.rpm pango-devel-1.6.0-16.el4_8.i386.rpm ia64: evolution28-pango-1.14.9-13.el4_8.ia64.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.ia64.rpm evolution28-pango-devel-1.14.9-13.el4_8.ia64.rpm pango-1.6.0-16.el4_8.i386.rpm pango-1.6.0-16.el4_8.ia64.rpm pango-debuginfo-1.6.0-16.el4_8.i386.rpm pango-debuginfo-1.6.0-16.el4_8.ia64.rpm pango-devel-1.6.0-16.el4_8.ia64.rpm x86_64: evolution28-pango-1.14.9-13.el4_8.x86_64.rpm evolution28-pango-debuginfo-1.14.9-13.el4_8.x86_64.rpm evolution28-pango-devel-1.14.9-13.el4_8.x86_64.rpm pango-1.6.0-16.el4_8.i386.rpm pango-1.6.0-16.el4_8.x86_64.rpm pango-debuginfo-1.6.0-16.el4_8.i386.rpm pango-debuginfo-1.6.0-16.el4_8.x86_64.rpm pango-devel-1.6.0-16.el4_8.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: pango-1.14.9-8.el5.i386.rpm pango-debuginfo-1.14.9-8.el5.i386.rpm x86_64: pango-1.14.9-8.el5.i386.rpm pango-1.14.9-8.el5.x86_64.rpm pango-debuginfo-1.14.9-8.el5.i386.rpm pango-debuginfo-1.14.9-8.el5.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: pango-debuginfo-1.14.9-8.el5.i386.rpm pango-devel-1.14.9-8.el5.i386.rpm x86_64: pango-debuginfo-1.14.9-8.el5.i386.rpm pango-debuginfo-1.14.9-8.el5.x86_64.rpm pango-devel-1.14.9-8.el5.i386.rpm pango-devel-1.14.9-8.el5.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: pango-1.14.9-8.el5.i386.rpm pango-debuginfo-1.14.9-8.el5.i386.rpm pango-devel-1.14.9-8.el5.i386.rpm ia64: pango-1.14.9-8.el5.i386.rpm pango-1.14.9-8.el5.ia64.rpm pango-debuginfo-1.14.9-8.el5.i386.rpm pango-debuginfo-1.14.9-8.el5.ia64.rpm pango-devel-1.14.9-8.el5.ia64.rpm ppc: pango-1.14.9-8.el5.ppc.rpm pango-1.14.9-8.el5.ppc64.rpm pango-debuginfo-1.14.9-8.el5.ppc.rpm pango-debuginfo-1.14.9-8.el5.ppc64.rpm pango-devel-1.14.9-8.el5.ppc.rpm pango-devel-1.14.9-8.el5.ppc64.rpm s390x: pango-1.14.9-8.el5.s390.rpm pango-1.14.9-8.el5.s390x.rpm pango-debuginfo-1.14.9-8.el5.s390.rpm pango-debuginfo-1.14.9-8.el5.s390x.rpm pango-devel-1.14.9-8.el5.s390.rpm pango-devel-1.14.9-8.el5.s390x.rpm x86_64: pango-1.14.9-8.el5.i386.rpm pango-1.14.9-8.el5.x86_64.rpm pango-debuginfo-1.14.9-8.el5.i386.rpm pango-debuginfo-1.14.9-8.el5.x86_64.rpm pango-devel-1.14.9-8.el5.i386.rpm pango-devel-1.14.9-8.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2010-0421 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2010 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFLnsAiXlSAg2UNWIIRAhr7AKCQMs0AzrTofQMDdmgOrps1dhCdHgCdGClf wYke9nKsdg0SvbtmyaahT/k=Y+aJ -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-292 2006-04-17 ---------------------------------------------------------------------Product : Fedora Core 5 Name : pango Version : 1.12.1 Release : 1.fc5.1 Summary : System for layout and rendering of internationalized text Description : Pango is a system for layout and rendering of internationalized text. ---------------------------------------------------------------------Update Information: Overview of changes between 1.12.0 and 1.12.1 ============================================* Fix non-OpenType fonts losing kerning in 1.12.0 [#336026, Denis Jacquerye] * Fix blurred underlines on Win32 [#332656, Tor Lillqvist] * Build fix when having both Win32 and FreeType cairo backends available [#337502, Alexander Larsson] * Bugs fixed in this release: 334802,336026,332656,337502 ---------------------------------------------------------------------* Fri Apr 7 2006 Matthias Clasen - 1.12.1-1.fc5.1 - Update to 1.12.1 ---------------------------------------------------------------------This update can be downloaded from: 871a2d036bcb23222c8a8f6cfbb18b501fe22723 SRPMS/pango-1.12.1-1.fc5.1.src.rpm 0c535411595cc2ef70758725b23eb8d9d9a1fe7c ppc/pango-1.12.1-1.fc5.1.ppc.rpm 8fdf1264463426f9c933ec3b4cf0bda71ee4ed12 ppc/pango-devel-1.12.1-1.fc5.1.ppc.rpm 575f1d8438a6d8c942e8f2e0428e4db457cd4dce ppc/debug/pango-debuginfo-1.12.1-1.fc5.1.ppc.rpm 37ebc51c326bfdafc4034cacd8f1877449a5c63b x86_64/pango-1.12.1-1.fc5.1.x86_64.rpm 15646e23d54e27bdc934c66baba5fa507d951b90 x86_64/pango-devel-1.12.1-1.fc5.1.x86_64.rpm 1e7335bc9cb0dceb88eb78a9c59d2a578cf9bebe x86_64/debug/pango-debuginfo-1.12.1-1.fc5.1.x86_64.rpm 6501cb5425c01dd7172be1d341cb7953ef2efdfc i386/pango-1.12.1-1.fc5.1.i386.rpm 6767e7a778fa9db572d8d4043636877f87db1628 i386/pango-devel-1.12.1-1.fc5.1.i386.rpm 074e56fd215448b2e2c51ad2fa27974b24d4294d i386/debug/pango-debuginfo-1.12.1-1.fc5.1.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.