CVE-2016-2795: High severity suse linux vulnerability
The graphite2::FileFace::gettablefn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2795?
CVE-2016-2795 has a moderate severity rating due to potential denial of service attacks.
How do I fix CVE-2016-2795?
To fix CVE-2016-2795, you should update to Graphite 2 version 1.3.6 or later, and ensure your Mozilla Firefox is updated to version 45.0 or later.
Which versions of software are affected by CVE-2016-2795?
CVE-2016-2795 affects several versions including Mozilla Firefox before 45.0, Firefox ESR versions before 38.7, and Graphite 2 versions before 1.3.6.
What types of attacks can CVE-2016-2795 enable?
CVE-2016-2795 allows remote attackers to cause denial of service or potentially exploit other unknown vulnerabilities.
Is there a workaround for CVE-2016-2795?
The best workaround for CVE-2016-2795 is to upgrade affected software to the patched versions to mitigate risks.