#VU19591 Buffer overflow in Pango - CVE-2019-1010238
Published: July 31, 2019 / Updated: February 10, 2022
Pango
Gnome Development Team
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing utf-8 strings in the pango_log2vis_get_embedding_levels() function in pango-bidi-type.c. A remote attacker can pass a specially crafted string to the application, trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.