The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.

Project Subscriptions

Vendors Products
Debian Linux Subscribe
Fedoraproject Subscribe
Mozilla Subscribe
Firefox Subscribe
Thunderbird Subscribe
Enterprise Linux Subscribe
Graphite2 Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-3477-1 iceweasel security update
Debian DSA Debian DSA DSA-3479-1 graphite2 security update
Debian DSA Debian DSA DSA-3491-1 icedove security update
EUVD EUVD EUVD-2016-2618 The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
Ubuntu USN Ubuntu USN USN-2902-1 graphite2 vulnerabilities
Ubuntu USN Ubuntu USN USN-2904-1 Thunderbird vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://blog.talosintel.com/2016/02/vulnerability-spotlight-libgraphite.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177520.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184623.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00053.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00055.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00052.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00058.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00088.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2016-0197.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2016-0258.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2016-0594.html cve-icon cve-icon
http://www.debian.org/security/2016/dsa-3477 cve-icon cve-icon
http://www.debian.org/security/2016/dsa-3479 cve-icon cve-icon
http://www.debian.org/security/2016/dsa-3491 cve-icon cve-icon
http://www.mozilla.org/security/announce/2016/mfsa2016-14.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html cve-icon cve-icon
http://www.securityfocus.com/bid/82991 cve-icon cve-icon
http://www.securitytracker.com/id/1035017 cve-icon cve-icon
http://www.talosintel.com/reports/TALOS-2016-0059/ cve-icon
http://www.ubuntu.com/usn/USN-2902-1 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-2904-1 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=1246093 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2016-1523 cve-icon
https://security.gentoo.org/glsa/201605-06 cve-icon cve-icon
https://security.gentoo.org/glsa/201701-35 cve-icon cve-icon
https://security.gentoo.org/glsa/201701-63 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2016-1523 cve-icon
History

Tue, 22 Oct 2024 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.2.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.2.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.3.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.4.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.2.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.2.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.3.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.4.0:*:*:*:*:*:*:*
Vendors & Products Mozilla firefox Esr

Mon, 21 Oct 2024 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox
CPEs cpe:2.3:a:mozilla:firefox_esr:38.5.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.5.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.5.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:38.6.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.5.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.5.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.5.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:38.6.0:*:*:*:*:*:*:*
Vendors & Products Mozilla firefox

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2024-08-05T23:02:11.560Z

Reserved: 2016-01-07T00:00:00

Link: CVE-2016-1523

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-02-13T02:59:08.900

Modified: 2025-04-12T10:46:40.837

Link: CVE-2016-1523

cve-icon Redhat

Severity : Critical

Publid Date: 2016-02-05T00:00:00Z

Links: CVE-2016-1523 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses