Vulnerabilities > CVE-2019-19308 - NULL Pointer Dereference vulnerability in Gnome Gnome-Font-Viewer 3.34.0

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
gnome
CWE-476

Summary

In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns NULL).

Vulnerable Configurations

Part Description Count
Application
Gnome
1

Common Weakness Enumeration (CWE)