Red Hat Bugzilla – Bug 1613550
CVE-2018-15120 pango: application crash triggered by unicode chars in pango-emoji.c
Last modified: 2018-09-17 10:38:51 EDT
A flaw was found in Pango since versions 1.40.8 up to newer. Typing certain invalid Emoji sequences into a GTK+ application can trigger a Reachable Assertion resulting in an application crash.
Statement: This issue did not affect the versions of pango as shipped with Red Hat Enterprise Linux 5, 6, and 7 as they did not include support for emojis.
References: https://mail.gnome.org/archives/distributor-list/2018-August/msg00001.html Upstream patch: https://gitlab.gnome.org/GNOME/pango/commit/71aaeaf020340412b8d012fe23a556c0420eda5f
Created pango tracking bugs for this issue: Affects: fedora-all [bug 1619831]
Acknowledgments: Name: Jeffery M Upstream: GNOME Project