CVE-2016-2791: Buffer Overflow
The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2791?
CVE-2016-2791 has been classified as a moderate severity vulnerability due to its potential for causing denial of service.
How do I fix CVE-2016-2791?
To fix CVE-2016-2791, update Graphite2 to version 1.3.6 or later and ensure your Mozilla Firefox is upgraded to version 45.0 or higher.
What software is affected by CVE-2016-2791?
CVE-2016-2791 affects Mozilla Firefox versions up to 44.0.2, Firefox ESR 38.x versions prior to 38.7, and specific versions of Graphite2 up to 1.3.5.
What impact does CVE-2016-2791 have?
The impact of CVE-2016-2791 includes potential buffer over-reads leading to denial of service attacks.
Who can exploit CVE-2016-2791?
CVE-2016-2791 can be exploited by remote attackers through crafted Graphite smart fonts.