CVE-2016-1969: Buffer Overflow
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1969?
CVE-2016-1969 has a medium severity rating due to its potential to cause denial of service through an out-of-bounds write.
How do I fix CVE-2016-1969?
To fix CVE-2016-1969, update Graphite 2 to version 1.3.6 or later and ensure your Firefox or Firefox ESR version is updated to at least 45.0 or 38.6.1 respectively.
What vulnerabilities are associated with CVE-2016-1969?
CVE-2016-1969 allows remote attackers to trigger denial of service through crafted Graphite smart fonts.
Which versions of software are affected by CVE-2016-1969?
CVE-2016-1969 affects Graphite 2 versions prior to 1.3.6 and various versions of Mozilla Firefox and Firefox ESR before specified updates.
Is there a workaround for CVE-2016-1969 if I can't update immediately?
While the best solution is to update, a temporary workaround could include disabling the use of Graphite fonts in your applications, if possible.