6.8

CVE-2009-1194

Exploit
Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long glyph string that triggers a heap-based buffer overflow, as demonstrated by a long document.location value in Firefox.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PangoPango Version <= 1.22
PangoPango Version1.2
PangoPango Version1.4
PangoPango Version1.6
PangoPango Version1.8
PangoPango Version1.10
PangoPango Version1.12
PangoPango Version1.14
PangoPango Version1.16
PangoPango Version1.18
PangoPango Version1.20
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.85% 0.885
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.