Another #Pango security hole, this time on text with long glyphstrings (such as, I think, Zalgo text, but maybe also a long document.location in Firefox). This one from 2009. (CVE-2009-1194 I think?)
An overview of the #Pango API (and HarfBuzz)
on 02015-08-05RHSA-2011:1325-01 (CVE-2011-3193) was an additional #security problem in #Pango and HarfBuzz — probably another arbitrary-code-execution hole in, this time, font file parsing. This was equally a bug in #Qt.
on 02015-08-05this #security bullshit (CVE-2011-0064 buffer overflow arbitrary code execution) is why I never want to use #Pango for anything. It’s the HarfBuzz OpenType “text shaping engine” that is responsible.
on 02015-08-05This is the function to draw a line of text in #Pango (and #GTK). It invokes draw_shaped_glyphs, which is private. It’s not mapped in lablgtk2.
this is the #Pango function to find out how wide #GTK thinks some text should be; it’s not mapped in lablgtk2.
on 02015-08-05apparently #GTK 3 no longer exposes low-level text drawing routines; instead you have to use fucking #Pango and #Cairo.
on 02015-08-05