CVE-2019-19308
Summary
| CVE | CVE-2019-19308 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-27 15:15:00 UTC |
| Updated | 2019-12-12 20:10:00 UTC |
| Description | In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns NULL). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| gnome-font-viewer/sushi-font-widget.c at 919dfbe684b75904563b8c6723c9778a4e00aad7 · GNOME/gnome-font-viewer · GitHub |
MISC |
github.com |
Third Party Advisory |
| NULL pointer dereference due to missing name section. (#17) · Issues · GNOME / GNOME Fonts · GitLab |
CONFIRM |
gitlab.gnome.org |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296075 Oracle Solaris 11.4 Support Repository Update (SRU) 21.69.0 Missing (CPUAPR2020)