2019-03-20 13:10:50 +00:00
{
2020-04-16 19:02:24 +00:00
"CVE_data_meta" : {
"ASSIGNER" : "cve-assign@distributedweaknessfiling.org" ,
"ID" : "CVE-2019-1010238" ,
"STATE" : "PUBLIC"
2019-07-19 17:00:49 +00:00
} ,
2020-04-16 19:02:24 +00:00
"affects" : {
"vendor" : {
"vendor_data" : [
2019-07-19 17:00:49 +00:00
{
2020-04-16 19:02:24 +00:00
"product" : {
"product_data" : [
2019-07-19 17:00:49 +00:00
{
2020-04-16 19:02:24 +00:00
"product_name" : "Pango" ,
"version" : {
"version_data" : [
2019-07-19 17:00:49 +00:00
{
2020-04-16 19:02:24 +00:00
"version_value" : "1.42 and later"
2019-07-19 17:00:49 +00:00
}
]
}
}
]
} ,
2020-04-16 19:02:24 +00:00
"vendor_name" : "Gnome"
2019-07-19 17:00:49 +00:00
}
]
}
2019-03-20 13:10:50 +00:00
} ,
2020-04-16 19:02:24 +00:00
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
2019-03-20 13:10:50 +00:00
{
2020-04-16 19:02:24 +00:00
"lang" : "eng" ,
"value" : "Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to functions like pango_itemize."
2019-07-19 17:00:49 +00:00
}
]
} ,
2020-04-16 19:02:24 +00:00
"problemtype" : {
"problemtype_data" : [
2019-07-19 17:00:49 +00:00
{
2020-04-16 19:02:24 +00:00
"description" : [
2019-07-19 17:00:49 +00:00
{
2020-04-16 19:02:24 +00:00
"lang" : "eng" ,
"value" : "Buffer Overflow"
2019-07-19 17:00:49 +00:00
}
]
}
]
} ,
2020-04-16 19:02:24 +00:00
"references" : {
"reference_data" : [
2019-07-19 17:00:49 +00:00
{
2020-04-16 19:02:24 +00:00
"url" : "https://gitlab.gnome.org/GNOME/pango/blob/master/pango/pango-bidi-type.c" ,
"refsource" : "MISC" ,
"name" : "https://gitlab.gnome.org/GNOME/pango/blob/master/pango/pango-bidi-type.c"
2019-07-31 20:00:52 +00:00
} ,
{
2020-04-16 19:02:24 +00:00
"refsource" : "UBUNTU" ,
"name" : "USN-4081-1" ,
"url" : "https://usn.ubuntu.com/4081-1/"
2019-08-11 23:00:50 +00:00
} ,
{
2020-04-16 19:02:24 +00:00
"refsource" : "DEBIAN" ,
"name" : "DSA-4496" ,
"url" : "https://www.debian.org/security/2019/dsa-4496"
2019-08-12 16:00:52 +00:00
} ,
{
2020-04-16 19:02:24 +00:00
"refsource" : "BUGTRAQ" ,
"name" : "20190812 [SECURITY] [DSA 4496-1] pango1.0 security update" ,
"url" : "https://seclists.org/bugtraq/2019/Aug/14"
2019-08-21 03:00:48 +00:00
} ,
{
2020-04-16 19:02:24 +00:00
"refsource" : "FEDORA" ,
"name" : "FEDORA-2019-547be4a683" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D6HWAHXJ2ZXINYMANHPFDDCJFWUQ57M4/"
2019-08-28 20:00:56 +00:00
} ,
{
2020-04-16 19:02:24 +00:00
"refsource" : "REDHAT" ,
"name" : "RHSA-2019:2571" ,
"url" : "https://access.redhat.com/errata/RHSA-2019:2571"
2019-08-29 10:00:48 +00:00
} ,
{
2020-04-16 19:02:24 +00:00
"refsource" : "REDHAT" ,
"name" : "RHSA-2019:2582" ,
"url" : "https://access.redhat.com/errata/RHSA-2019:2582"
2019-08-31 05:00:58 +00:00
} ,
{
2020-04-16 19:02:24 +00:00
"refsource" : "FEDORA" ,
"name" : "FEDORA-2019-155e34df5a" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VFFF4FY7SCAYT3EKTYPGRN6BVKZTH7Y7/"
2019-09-06 18:01:00 +00:00
} ,
{
2020-04-16 19:02:24 +00:00
"refsource" : "GENTOO" ,
"name" : "GLSA-201909-03" ,
"url" : "https://security.gentoo.org/glsa/201909-03"
2019-09-10 19:00:50 +00:00
} ,
{
2020-04-16 19:02:24 +00:00
"refsource" : "REDHAT" ,
"name" : "RHSA-2019:2594" ,
"url" : "https://access.redhat.com/errata/RHSA-2019:2594"
2019-10-11 04:01:00 +00:00
} ,
{
2020-04-16 19:02:24 +00:00
"refsource" : "REDHAT" ,
"name" : "RHBA-2019:2824" ,
"url" : "https://access.redhat.com/errata/RHBA-2019:2824"
2019-10-29 19:01:29 +00:00
} ,
{
2020-04-16 19:02:24 +00:00
"refsource" : "REDHAT" ,
"name" : "RHSA-2019:3234" ,
"url" : "https://access.redhat.com/errata/RHSA-2019:3234"
2020-04-14 14:04:09 -07:00
} ,
{
2020-04-16 19:02:24 +00:00
"url" : "https://www.oracle.com/security-alerts/cpuapr2020.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/security-alerts/cpuapr2020.html"
2019-03-20 13:10:50 +00:00
}
]
}
}