Vulnerability Description
libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Pango | >= 1.40.8, <= 1.42.3 |
| Canonical | Ubuntu Linux | 18.04 |
Related Weaknesses (CWE)
References
- http://52.117.224.77/xfce4-pdos.webmExploitThird Party Advisory
- https://github.com/GNOME/pango/blob/1.42.4/NEWSRelease NotesThird Party Advisory
- https://github.com/GNOME/pango/commit/71aaeaf020340412b8d012fe23a556c0420eda5fPatchThird Party Advisory
- https://i.redd.it/v7p4n2ptu0s11.jpgThird Party Advisory
- https://mail.gnome.org/archives/distributor-list/2018-August/msg00001.htmlPatchThird Party Advisory
- https://security.gentoo.org/glsa/201811-07Third Party Advisory
- https://usn.ubuntu.com/3750-1/Third Party Advisory
- https://www.exploit-db.com/exploits/45263ExploitPatchThird Party Advisory
- https://www.exploit-db.com/exploits/45263/ExploitPatchThird Party Advisory
- https://www.ign.com/articles/2018/10/16/ps4s-are-reportedly-being-bricked-and-soExploitThird Party Advisory
- https://www.reddit.com/r/PS4/comments/9o5efg/message_bricking_console_megathreadThird Party Advisory
- http://52.117.224.77/xfce4-pdos.webmExploitThird Party Advisory
- https://github.com/GNOME/pango/blob/1.42.4/NEWSRelease NotesThird Party Advisory
- https://github.com/GNOME/pango/commit/71aaeaf020340412b8d012fe23a556c0420eda5fPatchThird Party Advisory
- https://i.redd.it/v7p4n2ptu0s11.jpgThird Party Advisory
FAQ
What is CVE-2018-15120?
CVE-2018-15120 is a vulnerability with a CVSS score of 6.5 (MEDIUM). libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via c...
How severe is CVE-2018-15120?
CVE-2018-15120 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-15120?
Check the references section above for vendor advisories and patch information. Affected products include: Gnome Pango, Canonical Ubuntu Linux.