CVE-2017-7772: Buffer Overflow
A heap-based buffer overflow flaw related to "lz4::decompress" has been reported in graphite2. A remote attacker could exploit this issue to cause a crash, or, possibly, execute arbitrary code.
Other sources
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7772?
CVE-2017-7772 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2017-7772?
To fix CVE-2017-7772, update to the recommended versions of Firefox or Graphite2 provided in the advisory.
What systems are affected by CVE-2017-7772?
CVE-2017-7772 affects Firefox versions prior to 54 and certain versions of the Graphite2 library.
Can CVE-2017-7772 be exploited remotely?
Yes, CVE-2017-7772 can be exploited remotely by an attacker to cause a crash or potentially execute arbitrary code.
What is the nature of the flaw in CVE-2017-7772?
CVE-2017-7772 is a heap-based buffer overflow vulnerability found in the lz4::decompress function of the Graphite2 library.