CVE-2016-2790: High severity suse linux vulnerability
The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2790?
CVE-2016-2790 has a medium severity rating and can lead to denial of service.
How do I fix CVE-2016-2790?
To fix CVE-2016-2790, update Graphite2 to version 1.3.6 or later, and ensure Firefox is updated to versions above 45.0.
Which systems are affected by CVE-2016-2790?
CVE-2016-2790 affects Graphite2 versions below 1.3.6 as well as various versions of Mozilla Firefox and Firefox ESR prior to 45.0.
What type of vulnerability is CVE-2016-2790?
CVE-2016-2790 is a memory initialization vulnerability that allows remote attackers to exploit a data structure.
Can CVE-2016-2790 be exploited remotely?
Yes, CVE-2016-2790 can be exploited remotely, potentially leading to a denial of service.