Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-0020

44
FAUCET Score

CVE-2011-0020 describes a heap-based buffer overflow in the pango_ft2_font_render_box_glyph function within Pango versions 1.28.3 and earlier, specifically when the FreeType2 backend is enabled. This flaw allows user-assisted remote attackers to trigger a denial of service or potentially execute arbitrary code through a specially crafted font file. The vulnerability carries a CVSS score of 7.6, indicating high severity due to its network-based attack vector, high impact on confidentiality, integrity, and availability, though it requires high attack complexity. While not listed on CISA's KEV catalog or the Hot List, an exploit (EDB-35232) for heap corruption exists on ExploitDB, but there is no evidence of active exploitation, Metasploit modules, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.28.3CPE matchmatch criteria
cpe:2.3:a:gnome:pango:*:*:*:*:*:*:*:*
1.28.0CPE matchmatch criteria
cpe:2.3:a:gnome:pango:1.28.0:*:*:*:*:*:*:*
1.28.1CPE matchmatch criteria
cpe:2.3:a:gnome:pango:1.28.1:*:*:*:*:*:*:*
1.28.2CPE matchmatch criteria
cpe:2.3:a:gnome:pango:1.28.2:*:*:*:*:*:*:*
0.20CPE matchmatch criteria
cpe:2.3:a:pango:pango:0.20:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.6HIGH

AV:N/AC:H/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
18.94%
Probability of exploitation in next 30 days
EPSS Percentile
97.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-35232 · Jan 18, 2011
This CVE's current EPSS score of 0.1894 is in the 84th percentile among its peer group of 8,914 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: evolution28-pango-0:1.14.9-13.el4_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: pango-0:1.14.9-8.el5_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: pango-0:1.28.1-3.el6_0.3
View patch

Vendor Advisories (1)

redhatCVE-2011-0020Moderate

pango: Heap-based buffer overflow by rendering glyph box for certain FT_Bitmap objects

Jan 18, 2011

References

lists.opensuse.org / opensuse-security-announce/2011-04/msg00000.html
openwall.com / lists/oss-security/2011/01/18/6
Exploit
openwall.com / lists/oss-security/2011/01/20/2
Exploit
osvdb.org / 70596
bugs.launchpad.net / ubuntu/+source/pango1.0/+bug/696616
Exploit
bugzilla.gnome.org / show_bug.cgi
bugzilla.redhat.com / show_bug.cgi
Exploit
secunia.com / advisories/42934
secunia.com / advisories/43100
exchange.xforce.ibmcloud.com / vulnerabilities/64832
redhat.com / support/errata/RHSA-2011-0180.html
securityfocus.com / bid/45842
securitytracker.com / id
vupen.com / english/advisories/2011/0186
Vendor Advisory
vupen.com / english/advisories/2011/0238