CVE-2016-2798: Buffer Overflow
The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2798?
CVE-2016-2798 has a severity rating that suggests it can lead to denial of service attacks.
How do I fix CVE-2016-2798?
To fix CVE-2016-2798, users should update to Graphite 2 version 1.3.6 or newer and update Firefox to version 45.0 or later.
Which versions of Firefox are affected by CVE-2016-2798?
CVE-2016-2798 affects Firefox versions before 45.0 and Firefox ESR versions prior to 38.7.
How does CVE-2016-2798 affect system security?
CVE-2016-2798 allows remote attackers to potentially exploit the vulnerability to cause a buffer over-read leading to denial of service.
Are any other software besides Firefox vulnerable to CVE-2016-2798?
Yes, earlier versions of Graphite 2 up to 1.3.5 are also vulnerable to CVE-2016-2798.