4.3
CVSSv2

CVE-2018-15120

Published: 24/08/2018 Updated: 14/07/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

libpango in Pango 1.40.8 up to and including 1.42.3, as used in hexchat and other products, allows remote malicious users to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome pango

canonical ubuntu linux 18.04

Vendor Advisories

Pango could be made to crash if it opened a specially crafted file ...
libpango in Pango 1408 through 1423, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences ...

Exploits

# Exploit Title: Libpango 1408 - Denial of Service (PoC) # Date: 2018-08-06 # Exploit Author: Jeffery M # Vendor Homepage: wwwpangoorg/ # Software Link: ftpgnomeorg/pub/GNOME/sources/pango/140/pango-1409tarxz # Version: 1408+ # Tested on: Windows 7, Gentoo # CVE : CVE-2018-15120 # Patch : githubcom/GNOME/pango/ ...
Libpango version 1408 suffers from a denial of service vulnerability ...