Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-1523

Опубликовано: 05 фев. 2016
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.

A vulnerability has been discovered in Graphite2. An attacker able to trick an unsuspecting user into opening specially crafted font files in an application using Graphite2 could exploit these flaws to cause the application to crash or, potentially, execute arbitrary code with the privileges of the application.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1305813graphite2: Heap-based buffer overflow in context item handling functionality

EPSS

Процентиль: 74%
0.00837
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 9 лет назад

The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.

CVSS3: 6.5
nvd
больше 9 лет назад

The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.

CVSS3: 6.5
debian
больше 9 лет назад

The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Gra ...

suse-cvrf
больше 9 лет назад

Security update for MozillaFirefox

suse-cvrf
больше 9 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 74%
0.00837
Низкий

6.8 Medium

CVSS2