CVE-2016-1523: Null Pointer Dereference
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1523?
CVE-2016-1523 has a medium severity level, causing denial of service due to a NULL pointer dereference.
How do I fix CVE-2016-1523?
To fix CVE-2016-1523, update your affected application to a version that has patched this vulnerability.
Which versions are affected by CVE-2016-1523?
CVE-2016-1523 affects Mozilla Firefox versions before 43.0, Firefox ESR versions before 38.6.1, and Graphite 2 version 1.2.4.
Can CVE-2016-1523 be exploited remotely?
Yes, CVE-2016-1523 can be exploited remotely, allowing attackers to cause a denial of service.
What applications are impacted by CVE-2016-1523?
CVE-2016-1523 impacts applications relying on the Libgraphite library and specific versions of Mozilla Firefox and Firefox ESR.