Unrated severityNVD Advisory· Published Mar 18, 2010· Updated Apr 29, 2026
CVE-2010-0421
CVE-2010-0421
Description
Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's charmap and the Unicode property database.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- ftp.gnome.org/pub/GNOME/sources/pango/1.27/pango-1.27.1.tar.bz2nvdPatch
- lists.opensuse.org/opensuse-security-announce/2010-04/msg00002.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlnvd
- secunia.com/advisories/39041nvd
- securitytracker.com/idnvd
- www.debian.org/security/2010/dsa-2019nvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2010-0140.htmlnvd
- www.securityfocus.com/bid/38760nvd
- www.vupen.com/english/advisories/2010/0627nvd
- www.vupen.com/english/advisories/2010/0661nvd
- www.vupen.com/english/advisories/2010/1552nvd
- bugzilla.redhat.com/show_bug.cginvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9417nvd
News mentions
0No linked articles in our index yet.