CVE-2019-19308

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-19308
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-19308.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-19308
Related
Published
2019-11-27T15:15:11Z
Modified
2025-01-08T05:59:35.848782Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In texttoglyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns NULL).

References

Affected packages

Debian:11 / gnome-font-viewer

Package

Name
gnome-font-viewer
Purl
pkg:deb/debian/gnome-font-viewer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.34.0-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / gnome-font-viewer

Package

Name
gnome-font-viewer
Purl
pkg:deb/debian/gnome-font-viewer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.34.0-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / gnome-font-viewer

Package

Name
gnome-font-viewer
Purl
pkg:deb/debian/gnome-font-viewer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.34.0-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:11 / gnome-sushi

Package

Name
gnome-sushi
Purl
pkg:deb/debian/gnome-sushi?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.38.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / gnome-sushi

Package

Name
gnome-sushi
Purl
pkg:deb/debian/gnome-sushi?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.38.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / gnome-sushi

Package

Name
gnome-sushi
Purl
pkg:deb/debian/gnome-sushi?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.38.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Git / github.com/gnome/gnome-font-viewer

Affected ranges

Type
GIT
Repo
https://github.com/gnome/gnome-font-viewer
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

3.*

3.10.0
3.12.0
3.13.90
3.14.0
3.15.90
3.16.0
3.16.2
3.20.0
3.20.2
3.22.0
3.23.91
3.24.0
3.25.90
3.26.0
3.27.0
3.27.90
3.28.0
3.3.2
3.3.2.1
3.3.92
3.30.0
3.32.0
3.33.4
3.33.90
3.34.0
3.4.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.90
3.5.91
3.5.92
3.6.0
3.7.3
3.7.4
3.7.5
3.7.91
3.8.0
3.9.90