Summary
The remote host is missing an update to pango1.0
announced via advisory USN-773-1.
Solution
The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS:
libpango1.0-0 1.12.3-0ubuntu3.1
Ubuntu 8.04 LTS:
libpango1.0-0 1.20.5-0ubuntu1.1
Ubuntu 8.10:
libpango1.0-0 1.22.2-0ubuntu1.1
After a standard system upgrade you need to restart your session to effect the necessary changes.
https://secure1.securityspace.com/smysecure/catid.html?in=USN-773-1
Insight
Will Drewry discovered that Pango incorrectly handled rendering text with long glyphstrings. If a user were tricked into displaying specially crafted data with applications linked against Pango, such as Firefox, an attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program.
Severity
Classification
-
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities