Upstream information
Description
Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long glyph string that triggers a heap-based buffer overflow, as demonstrated by a long document.location value in Firefox.NVD CVSS v2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entries: 492773, 522109, 534701, 586526, 648732 SUSE Security Advisories:- SUSE-SA:2009:039, published Mon, 27 Jul 2009 09:00:00 +0000
- SUSE-SA:2009:042, published Thu, 06 Aug 2009 10:00:00 +0000
- SUSE-SR:2009:012, published Fri, 03 Jul 2009 16:00:00 +0000
- SUSE-SR:2010:004, published Tue, 16 Feb 2010 11:00:00 +0000
List of released packages
List of products where fixes are in QA
SUSE Linux Enterprise 11 GA DEBUGINFOSUSE Linux Enterprise 11 GA DEBUGINFO
SUSE Linux Enterprise Desktop 11 GA
SUSE Linux Enterprise Desktop 11 GA
SUSE Linux Enterprise SDK 11 GA
SUSE Linux Enterprise SDK 11 GA
SUSE Linux Enterprise Server 11 GA
SUSE Linux Enterprise Server 11 GA
