Denial of Service Risk in Pango Library Affecting HexChat and Other Products
CVE-2018-15120
6.5MEDIUM
Summary
The Pango library, utilized in various applications including HexChat, is susceptible to a denial of service condition. Through specially crafted Unicode text, remote attackers can trigger application crashes or potentially introduce unspecified impacts. This vulnerability spans Pango versions 1.40.8 to 1.42.3, underscoring the importance of updating to secure versions to mitigate risk.
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved