CVE Database
/

CVE-2019-18397

Back to search

CVE-2019-18397

Published: Nov 13, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses FriBidi for text layout calculations. Examples include any GNOME or GTK+ based application that uses Pango for text layout, as this internally uses FriBidi for bidirectional text layout. For example, the attacker can construct a crafted text file to be opened in GEdit, or a crafted IRC message to be viewed in HexChat.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2019-7075bc4ff8
vendor-advisory
x_refsource_FEDORA
RHSA-2019:4326
vendor-advisory
x_refsource_REDHAT
FEDORA-2019-533a72fec5
vendor-advisory
x_refsource_FEDORA
RHSA-2019:4361
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0291
vendor-advisory
x_refsource_REDHAT
GLSA-202003-41
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now