52.117.224.77
http://52.117.224.77/xfce4-pdos.webm CVE-2018-15120
MEDIUM
Libpango 1.40.8 - Denial of Service (PoC)
Record summary
CVE-2018-15120 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.
Description
libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLibpango 1.40.8 - Denial of Service (PoC)ExploitDB exploitby Jeffery MNot analyzed1 file
References
11github.comConfirmation
https://github.com/GNOME/pango/blob/1.42.4/NEWS github.comConfirmation
https://github.com/GNOME/pango/commit/71aaeaf020340412b8d012fe23a556c0420eda5f i.redd.it
https://i.redd.it/v7p4n2ptu0s11.jpg [distributor-list] 20180820 A critical pango fixmailing list
https://mail.gnome.org/archives/distributor-list/2018-August/msg00001.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-15120 GLSA-201811-07Vendor advisory
https://security.gentoo.org/glsa/201811-07 USN-3750-1Vendor advisory
https://usn.ubuntu.com/3750-1 45263exploit
https://www.exploit-db.com/exploits/45263 ign.com
https://www.ign.com/articles/2018/10/16/ps4s-are-reportedly-being-bricked-and-sony-is-working-on-a-fix reddit.com
https://www.reddit.com/r/PS4/comments/9o5efg/message_bricking_console_megathread