FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

Revision:  372964
Date:      2014-11-20
Time:      21:30:29Z
Committer: rakuco

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
4b172278-3f46-11de-becb-001cc0377035pango -- integer overflow

oCERT reports:

Pango suffers from a multiplicative integer overflow which may lead to a potentially exploitable, heap overflow depending on the calling conditions.

For example, this vulnerability is remotely reachable in Firefox by creating an overly large document.location value but only results in a process-terminating, allocation error (denial of service).

The affected function is pango_glyph_string_set_size. An overflow check when doubling the size neglects the overflow possible on the subsequent allocation.


Discovery 2009-02-22
Entry 2009-05-13
Modified 2009-10-01
pango
linux-pango
linux-f8-pango
linux-f10-pango
lt 1.24

34870
CVE-2009-1194
http://secunia.com/advisories/35021/