CVE-2016-1522: Buffer Overflow
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1522?
CVE-2016-1522 has a severity rating that can lead to denial of service or possible arbitrary code execution.
How do I fix CVE-2016-1522?
To fix CVE-2016-1522, update to the latest version of affected software such as Firefox or its derivatives.
Which versions of Firefox are affected by CVE-2016-1522?
CVE-2016-1522 affects Firefox versions prior to 43.0 and Firefox ESR versions prior to 38.6.1.
Is CVE-2016-1522 present in Mozilla Thunderbird?
Yes, CVE-2016-1522 can also affect certain versions of Mozilla Thunderbird that use the vulnerable Graphite2 library.
How can CVE-2016-1522 be exploited?
CVE-2016-1522 can be exploited by remote attackers through crafted inputs that trigger recursive load calls leading to a buffer overflow.