CVE-2018-15120
MEDIUMPango 1.40.8-1.42.3 - Denial of Service via Invalid Unicode Sequences
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-15120. PoCs published by Jeffery M.
AI-analyzed exploit summary This exploit triggers a denial of service (DoS) in Libpango 1.40.8+ by sending a malformed Unicode sequence via IRC, causing an assertion failure in the Emoji iter code. The PoC connects to an IRC server and sends a crafted message to exploit the vulnerability.
Description
libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.
Exploits (1)
This exploit triggers a denial of service (DoS) in Libpango 1.40.8+ by sending a malformed Unicode sequence via IRC, causing an assertion failure in the Emoji iter code. The PoC connects to an IRC server and sends a crafted message to exploit the vulnerability.
References (11)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H