Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-0020Improper Restriction of Operations within the Bounds of a Memory Buffer in Pango

Severity
7.6HIGHNVD
EPSS
5.7%
top 9.58%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 24
Latest updateMay 3

Description

Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.

CVSS vector

AV:N/AC:H/C:C/I:C/A:CExploitability: 4.9 | Impact: 10.0

Affected Packages2 packages

NVDgnome/pango1.28.3+3
NVDpango/pango35 versions+34

🔴Vulnerability Details

3
GHSA
GHSA-5c8w-jg4w-gcj2: Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render2022-05-03
CVEList
CVE-2011-0020: Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render2011-01-24
OSV
CVE-2011-0020: Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render2011-01-24

💥Exploits & PoCs

1
Exploit-DB
Pango Font Parsing - 'pangoft2-render.c' Heap Corruption2011-01-18

📋Vendor Advisories

3
Ubuntu
Pango vulnerabilities2011-03-02
Red Hat
pango: Heap-based buffer overflow by rendering glyph box for certain FT_Bitmap objects2011-01-18
Debian
CVE-2011-0020: pango1.0 - Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pa...2011

💬Community

1
Bugzilla
CVE-2011-0020 pango: Heap-based buffer overflow by rendering glyph box for certain FT_Bitmap objects2011-01-20
CVE-2011-0020 — Gnome Pango vulnerability | cvebase