CVE-2019-18397
Summary
| CVE | CVE-2019-18397 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-13 14:15:00 UTC |
| Updated | 2023-11-07 03:06:00 UTC |
| Description | A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses FriBidi for text layout calculations. Examples include any GNOME or GTK+ based application that uses Pango for text layout, as this internally uses FriBidi for bidirectional text layout. For example, the attacker can construct a crafted text file to be opened in GEdit, or a crafted IRC message to be viewed in HexChat. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 30 Update: fribidi-1.0.5-5.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: fribidi-1.0.5-5.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 30 Update: fribidi-1.0.5-5.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Truncate isolate_level to FRIBIDI_BIDI_MAX_EXPLICIT_LEVEL · fribidi/fribidi@034c6e9 · GitHub |
MISC |
github.com |
Patch |
| CVE-2019-18397 |
MISC |
security-tracker.debian.org |
Third Party Advisory |
| GNU FriBidi: Heap-based buffer overflow (GLSA 202003-41) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| '[oss-security] CVE-2019-18397 - Stack buffer overflow in GNU FriBidi >= 1.0.0' - MARC |
MISC |
marc.info |
Third Party Advisory |
| #944327 - fribidi: CVE-2019-18397 - Debian Bug report logs |
CONFIRM |
bugs.debian.org |
Issue Tracking, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| [SECURITY] Fedora 31 Update: fribidi-1.0.5-5.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 376906 Alibaba Cloud Linux Security Update for fribidi (ALINUX2-SA-2020:0004)
- 500193 Alpine Linux Security Update for fribidi
- 503934 Alpine Linux Security Update for fribidi
- 750026 SUSE Enterprise Linux Security Update for fribidi (SUSE-SU-2021:1655-1)
- 750202 OpenSUSE Security Update for fribidi (openSUSE-SU-2021:0763-1)
- 750783 OpenSUSE Security Update for fribidi (openSUSE-SU-2021:1655-1)