CVE-2016-2801: Buffer Overflow
The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2797.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2801?
CVE-2016-2801 has been classified as a moderate severity vulnerability due to its potential to cause denial of service through buffer over-read.
How do I fix CVE-2016-2801?
To mitigate CVE-2016-2801, you should upgrade Graphite2 to version 1.3.6 or later, and update affected versions of Mozilla Firefox and Firefox ESR.
What versions are affected by CVE-2016-2801?
CVE-2016-2801 affects Graphite2 versions prior to 1.3.6 and Mozilla Firefox versions before 45.0, along with several Firefox ESR versions.
What kind of attack does CVE-2016-2801 allow?
CVE-2016-2801 allows remote attackers to execute a denial of service attack through a crafted font file, causing a buffer over-read.
Is CVE-2016-2801 specific to a certain software platform?
Yes, CVE-2016-2801 mainly affects systems running specific versions of Graphite2, Mozilla Firefox, and Firefox ESR across various Linux distributions.