SCIENTIFIC-LINUX-ERRATA Archives

February 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Troy Dawson <[log in to unmask]>
Reply To:
Troy Dawson <[log in to unmask]>
Date:
Tue, 1 Feb 2011 12:31:32 -0600
Content-Type:
text/plain
Parts/Attachments:
text/plain (42 lines)
Synopsis:	Moderate: pango security update
Issue date:	2011-01-27
CVE Names:	CVE-2011-0020

An input sanitization flaw, leading to a heap-based buffer overflow, was
found in the way Pango displayed font files when using the FreeType font
engine back end. If a user loaded a malformed font file with an 
application that uses Pango, it could cause the application to crash or, 
possibly, execute arbitrary code with the privileges of the user running 
the application. (CVE-2011-0020)

After installing the updated packages, you must restart your system or 
restart your X session for the update to take effect.

SL 4.x

      SRPMS:
evolution28-pango-1.14.9-13.el4_10.src.rpm
      i386:
evolution28-pango-1.14.9-13.el4_10.i386.rpm
evolution28-pango-devel-1.14.9-13.el4_10.i386.rpm
      x86_64:
evolution28-pango-1.14.9-13.el4_10.i386.rpm
evolution28-pango-1.14.9-13.el4_10.x86_64.rpm
evolution28-pango-devel-1.14.9-13.el4_10.x86_64.rpm

SL 5.x

      SRPMS:
pango-1.14.9-8.el5_6.2.src.rpm
      i386:
pango-1.14.9-8.el5_6.2.i386.rpm
pango-devel-1.14.9-8.el5_6.2.i386.rpm
      x86_64:
pango-1.14.9-8.el5_6.2.i386.rpm
pango-1.14.9-8.el5_6.2.x86_64.rpm
pango-devel-1.14.9-8.el5_6.2.i386.rpm
pango-devel-1.14.9-8.el5_6.2.x86_64.rpm

-Connie Sieh
-Troy Dawson

ATOM RSS1 RSS2