CVE-2016-2052: High severity harfbuzz vulnerability
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2052?
The severity of CVE-2016-2052 is classified as high due to the potential for denial of service and other impacts from exploited vulnerabilities.
How do I fix CVE-2016-2052?
To remediate CVE-2016-2052, update HarfBuzz to version 1.0.6 or later, and update Google Chrome to version 48.0.2564.82 or later.
What type of vulnerabilities are associated with CVE-2016-2052?
CVE-2016-2052 is associated with multiple unspecified vulnerabilities that could lead to denial of service via crafted data.
Which versions of HarfBuzz are affected by CVE-2016-2052?
HarfBuzz versions before 1.0.6 are affected by CVE-2016-2052.
Which versions of Google Chrome are impacted by CVE-2016-2052?
Google Chrome versions before 48.0.2564.82 are impacted by CVE-2016-2052.