Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-1523

Опубликовано: 13 фев. 2016
Источник: debian
EPSS Низкий

Описание

The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
graphite2fixed1.3.5-1package
iceweaselfixed44.0-1package
iceweaselend-of-lifesqueezepackage
icedovefixed38.6.0-1package
icedoveend-of-lifesqueezepackage

Примечания

  • http://www.talosintel.com/reports/TALOS-2016-0059/

  • http://blog.talosintel.com/2016/02/vulnerability-spotlight-libgraphite.html

  • https://www.mozilla.org/en-US/security/advisories/mfsa2016-14/

EPSS

Процентиль: 74%
0.00837
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 9 лет назад

The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.

redhat
больше 9 лет назад

The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.

CVSS3: 6.5
nvd
больше 9 лет назад

The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.

suse-cvrf
больше 9 лет назад

Security update for MozillaFirefox

suse-cvrf
больше 9 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 74%
0.00837
Низкий