{"id":"JLSEC-2026-455","summary":"Gnome Pango 1.42 and later is affected by: Buffer Overflow","details":"Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: `pango_log2vis_get_embedding_levels`, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to functions like `pango_itemize`.","modified":"2026-07-25T18:24:29.435405472Z","published":"2026-05-07T14:27:30.173Z","upstream":["CVE-2019-1010238","GHSA-wwvc-98fq-c42m","EUVD-2019-1980"],"database_specific":{"license":"CC-BY-4.0","sources":[{"published":"2019-07-19T17:15:11.690Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2019-1010238","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010238","database_specific":{"status":"Modified"},"id":"CVE-2019-1010238","imported":"2026-07-17T21:55:47.011Z","modified":"2026-06-17T02:09:53.650Z"},{"html_url":"https://github.com/advisories/GHSA-wwvc-98fq-c42m","id":"GHSA-wwvc-98fq-c42m","imported":"2026-07-17T21:55:47.160Z","modified":"2024-04-04T01:18:58Z","published":"2022-05-24T16:50:42Z","url":"https://api.github.com/advisories/GHSA-wwvc-98fq-c42m"},{"id":"EUVD-2019-1980","imported":"2026-07-17T21:55:51.497Z","modified":"2024-08-05T03:07:18Z","published":"2019-07-19T16:42:41Z","url":"https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2019-1980","html_url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-1980"}]},"references":[{"type":"WEB","url":"https://access.redhat.com/errata/RHBA-2019:2824"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:2571"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:2582"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:2594"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:3234"},{"type":"WEB","url":"https://github.com/advisories/GHSA-wwvc-98fq-c42m"},{"type":"WEB","url":"https://gitlab.gnome.org/GNOME/pango/-/commits/main/pango/pango-bidi-type.c"},{"type":"WEB","url":"https://gitlab.gnome.org/GNOME/pango/-/issues/342"},{"type":"WEB","url":"https://gitlab.gnome.org/GNOME/pango/blob/master/pango/pango-bidi-type.c"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D6HWAHXJ2ZXINYMANHPFDDCJFWUQ57M4"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D6HWAHXJ2ZXINYMANHPFDDCJFWUQ57M4/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VFFF4FY7SCAYT3EKTYPGRN6BVKZTH7Y7"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VFFF4FY7SCAYT3EKTYPGRN6BVKZTH7Y7/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D6HWAHXJ2ZXINYMANHPFDDCJFWUQ57M4"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VFFF4FY7SCAYT3EKTYPGRN6BVKZTH7Y7"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010238"},{"type":"WEB","url":"https://seclists.org/bugtraq/2019/Aug/14"},{"type":"WEB","url":"https://security.gentoo.org/glsa/201909-03"},{"type":"WEB","url":"https://usn.ubuntu.com/4081-1"},{"type":"WEB","url":"https://usn.ubuntu.com/4081-1/"},{"type":"WEB","url":"https://www.debian.org/security/2019/dsa-4496"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"}],"affected":[{"package":{"name":"Pango_jll","ecosystem":"Julia","purl":"pkg:julia/Pango_jll?uuid=36c8627f-9965-5494-a995-c6b170f724f3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.47.0+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-455.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V2","score":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}