CVE-2017-7776: Buffer Overflow
An out of bounds read flaw related to "graphite2::Silf::getClassGlyph" has been reported in graphite2. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
Other sources
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7776?
CVE-2017-7776 has a moderate severity level due to its potential for causing application crashes or disclosing sensitive information.
How do I fix CVE-2017-7776?
To resolve CVE-2017-7776, update Firefox to version 118.0.2-1 or Firefox ESR to an acceptable patched version.
Which software is affected by CVE-2017-7776?
CVE-2017-7776 affects Firefox versions prior to 54 and the Graphite2 library versions before 1.3.10.
Can CVE-2017-7776 be exploited remotely?
Yes, CVE-2017-7776 can potentially be exploited by attackers to access sensitive memory remotely.
Is there a specific patch for CVE-2017-7776 in the Graphite2 library?
Yes, to mitigate CVE-2017-7776, you should update Graphite2 to at least versions 1.3.13-7 or 1.3.14-1.