CVE-2016-2793: Buffer Overflow
CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2793?
CVE-2016-2793 has a severity rating of medium as it allows remote attackers to cause a denial of service.
How do I fix CVE-2016-2793?
To fix CVE-2016-2793, update to Graphite 2 version 1.3.6 or later and ensure that your browser is updated to the latest version.
Which systems are affected by CVE-2016-2793?
CVE-2016-2793 affects multiple versions of Firefox, Firefox ESR, and Graphite 2 across various operating systems including Oracle Linux and openSUSE.
What impact does CVE-2016-2793 have?
CVE-2016-2793 can lead to denial of service due to a buffer over-read when processing specially crafted Graphite smart fonts.
Is there a workaround for CVE-2016-2793 if I can't update immediately?
As a workaround for CVE-2016-2793, users can avoid opening documents or files that utilize Graphite smart fonts until a patch is applied.