vendor:
by:
Jeffery M
6.5
CVSS
MEDIUM
Denial of Service
CWE
Product Name:
Affected Version From: 1.40.8
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2018-15120
CPE:
Metasploit:
https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2018-15120/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2018-15120/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2018-15120/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2018-15120/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2018-15120/
Platforms Tested: Windows 7, Gentoo
2018
Libpango 1.40.8 – Denial of Service (PoC)
Invalid Unicode sequences can trick the Emoji iter code into returning an empty segment, which then triggers an assertion in the itemizer.
Mitigation:
Apply the patch provided by the vendor.