PoC Index

CVE-2011-0020

HIGH 7.6EPSS 18.9%

Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.

CVSS v2.0
7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
EPSS
18.94% chance of exploitation in the next 30 days, 97th percentile
Published
2011-01-24
Updated
2024-08-06

ExploitDB entries (1)

References

Related