CVE-2016-2792: Buffer Overflow
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2800.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2792?
CVE-2016-2792 is classified as a medium severity vulnerability that can lead to denial of service through buffer over-read.
How do I fix CVE-2016-2792?
To mitigate CVE-2016-2792, upgrade Graphite 2 to version 1.3.6 or later and update affected versions of Mozilla Firefox and Firefox ESR to their respective patched versions.
Which software is affected by CVE-2016-2792?
CVE-2016-2792 affects Graphite 2 versions before 1.3.6 and Mozilla Firefox versions before 45.0, along with various versions of Firefox ESR.
What type of attack does CVE-2016-2792 facilitate?
CVE-2016-2792 allows remote attackers to execute a denial of service attack via crafted Graphite smart fonts.
Is CVE-2016-2792 still a threat?
CVE-2016-2792 is no longer a threat if all affected software has been updated to the latest versions.