Pango: Buffer overflow A buffer overflow in Pango might allow an attacker to execute arbitrary code. pango 2019-09-06 2019-09-06 692110 remote 1.42.4-r2 1.42.4-r2

Pango is a library for layout and rendering of internationalized text.

A buffer overflow has been discovered in Pango’s pango_log2vis_get_embedding_levels function.

A remote attacker could entice a user to process a specially crafted string with functions like pango_itemize, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition.

There is no known workaround at this time.

All Pango users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=x11-libs/pango-1.42.4-r2"
CVE-2019-1010238 b-man b-man