Ubuntu has issued an advisory on August 22: https://usn.ubuntu.com/3750-1/
Working on this.
Assignee: bugsquad => rverschelde
The patch for CVE-2018-15120 is on the pango/pango-emoji.c file, which is not present in our version 1.40.6. It seems that the feature was added in 1.40.8, so we're safe: https://github.com/GNOME/pango/blob/1.40.8/NEWS Cauldron ships 1.42.4 already so it's good too.
Status: NEW => RESOLVEDResolution: (none) => INVALID