CVE-2016-1526: Buffer Overflow
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1526?
CVE-2016-1526 has been categorized as a moderate severity vulnerability.
How do I fix CVE-2016-1526?
To fix CVE-2016-1526, update to the latest version of affected software that contains the security patch.
What are the affected software versions for CVE-2016-1526?
CVE-2016-1526 affects specific versions of Mozilla Firefox, Firefox ESR, and Libgraphite.
Can CVE-2016-1526 cause data leaks?
Yes, CVE-2016-1526 can allow remote attackers to obtain sensitive information.
Is CVE-2016-1526 related to Denial of Service?
Yes, CVE-2016-1526 may lead to a denial of service condition due to improper validation.