Upstream information
Description
Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's charmap and the Unicode property database.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
Novell/SUSE information
Novell Bugzilla entry: 581764, 597947 SUSE Security Advisories:- SUSE-SR:2010:009, published Wed, 14 Apr 2010 13:00:00 +0000
- SUSE-SR:2010:012, published Tue, 25 May 2010 12:00:00 +0000
- SUSE-SR:2010:013, published Mon, 14 Jun 2010 13:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Server for SAP 10 SP2 |
| sled10-sp2.x86 sles10-sp2.ppc sles10-sp2.ia64 sles10-sp2.x86-64 sles10-sp2.x86 sle10-sp2-sdk.ppc sles10-sp2.s390x sled10-sp2.x86-64 ZYPP Patch Nr: 6894 |
| SUSE Linux Enterprise SDK 10 SP2 |
| sled10-sp2.x86 sles10-sp2.ppc sles10-sp2.ia64 sles10-sp2.x86-64 sles10-sp2.x86 sle10-sp2-sdk.ppc sles10-sp2.s390x sled10-sp2.x86-64 ZYPP Patch Nr: 6894 |
| Open Enterprise Server |
| sles9-nlpos.x86 core9.ia64 core9.x86 core9.ppc core9.s390 core9.x86-64 core9.s390x sles9-oes.x86 YOU Patch Nr: 12614 |
| SUSE CORE 9 for AMD64 and Intel EM64T |
| Builds YOU Patch Nr: 12732 |
| SUSE Linux Enterprise Desktop 10 SP3 for x86 SUSE Linux Enterprise Server 10 SP3 |
| sles10-sp3.x86 sles10-sp3.x86-64 sles10-sp3.ia64 sles10-sp3.s390x sled10-sp3.x86-64 sles10-sp3.ppc sled10-sp3.x86 sle10-sp3-sdk.ppc ZYPP Patch Nr: 6895 |
| SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T SUSE Linux Enterprise SDK 10 SP3 SUSE Linux Enterprise Server 10 SP3 SUSE Linux Enterprise Server for SAP 10 SP3 |
| sles10-sp3.x86 sles10-sp3.x86-64 sles10-sp3.ia64 sles10-sp3.s390x sled10-sp3.x86-64 sles10-sp3.ppc sled10-sp3.x86 sle10-sp3-sdk.ppc ZYPP Patch Nr: 6895 |
| SUSE Linux Enterprise SDK 10 SP3 |
| sles10-sp3.x86 sles10-sp3.x86-64 sles10-sp3.ia64 sles10-sp3.s390x sled10-sp3.x86-64 sles10-sp3.ppc sled10-sp3.x86 sle10-sp3-sdk.ppc ZYPP Patch Nr: 6895 |
| SUSE Linux Enterprise Server 10 SP3 |
| sles10-sp3.x86 sles10-sp3.x86-64 sles10-sp3.ia64 sles10-sp3.s390x sled10-sp3.x86-64 sles10-sp3.ppc sled10-sp3.x86 sle10-sp3-sdk.ppc ZYPP Patch Nr: 6895 |
| SUSE Linux Enterprise Server 10 SP3 |
| sles10-sp3.x86 sles10-sp3.x86-64 sles10-sp3.ia64 sles10-sp3.s390x sled10-sp3.x86-64 sles10-sp3.ppc sled10-sp3.x86 sle10-sp3-sdk.ppc ZYPP Patch Nr: 6895 |
