Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-1526

Опубликовано: 13 фев. 2016
Источник: debian
EPSS Низкий

Описание

The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
graphite2fixed1.3.5-1package
iceweaselfixed44.0-1package
iceweaselend-of-lifesqueezepackage
icedovefixed38.6.0-1package
icedoveend-of-lifesqueezepackage

Примечания

  • http://blog.talosintel.com/2016/02/vulnerability-spotlight-libgraphite.html

  • Talos Blog mentions this CVE, but it is not listed in

  • http://talosintel.com/vulnerability-reports/

  • https://www.mozilla.org/en-US/security/advisories/mfsa2016-14/

EPSS

Процентиль: 66%
0.00519
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 9 лет назад

The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.

redhat
больше 9 лет назад

The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.

CVSS3: 8.1
nvd
больше 9 лет назад

The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.

CVSS3: 8.1
github
больше 3 лет назад

The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.

fstec
больше 9 лет назад

Уязвимость браузера Firefox ESR, программного средства рендеринга Graphite 2, почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании или получить конфиденциальную информацию

EPSS

Процентиль: 66%
0.00519
Низкий