CVE-2016-1977: Buffer Overflow
The Machine::Code::decoder::analysis::setref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted Graphite smart font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1977?
CVE-2016-1977 is considered a critical vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2016-1977?
To mitigate CVE-2016-1977, update Graphite 2 to version 1.3.6 or later, and ensure Firefox is updated to version 45.0 or higher.
Which software is affected by CVE-2016-1977?
CVE-2016-1977 affects Graphite 2 prior to 1.3.6 and multiple versions of Mozilla Firefox and Firefox ESR.
What kind of attack is possible with CVE-2016-1977?
CVE-2016-1977 allows attackers to execute arbitrary code or cause stack memory corruption through specially crafted Graphite smart fonts.
Is CVE-2016-1977 still a risk in current software versions?
CVE-2016-1977 should not pose a risk if you are using updated versions of affected software, specifically Graphite 2 and Firefox.