PublicDateAtUSN: 2016-07-19 Candidate: CVE-2015-8947 PublicDate: 2016-07-19 10:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8947 https://github.com/behdad/harfbuzz/issues/139#issuecomment-146984679 https://ubuntu.com/security/notices/USN-3067-1 Description: hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052. Ubuntu-Description: Notes: Bugs: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-8947 Priority: medium Discovered-by: Kostya Serebryany Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H [7.6 HIGH] Patches_harfbuzz: upstream: https://cgit.freedesktop.org/harfbuzz/commit/?id=f96664974774bfeb237a7274f512f64aaafb201e upstream_harfbuzz: released (1.2.6-1) precise_harfbuzz: DNE precise/esm_harfbuzz: DNE trusty_harfbuzz: released (0.9.27-1ubuntu1.1) trusty/esm_harfbuzz: released (0.9.27-1ubuntu1.1) vivid/stable-phone-overlay_harfbuzz: ignored (reached end-of-life) vivid/ubuntu-core_harfbuzz: DNE wily_harfbuzz: ignored (reached end-of-life) xenial_harfbuzz: released (1.0.1-1ubuntu0.1) esm-infra/xenial_harfbuzz: released (1.0.1-1ubuntu0.1) yakkety_harfbuzz: not-affected (1.2.6-2) zesty_harfbuzz: not-affected (1.2.6-2) devel_harfbuzz: not-affected (1.2.6-2)