PublicDateAtUSN: 2016-02-08 Candidate: CVE-2016-1521 PublicDate: 2016-02-13 02:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1521 http://www.talosintel.com/reports/TALOS-2016-0058/ http://www.talosintel.com/reports/TALOS-2016-0061/ http://blog.talosintel.com/2016/02/vulnerability-spotlight-libgraphite.html https://ubuntu.com/security/notices/USN-2902-1 Description: The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Yves Younan Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_graphite2: upstream: https://github.com/silnrsi/graphite/commit/6c50e793e5879a0aaf830fcdd16841dd28906f8b (0058) upstream: https://github.com/silnrsi/graphite/commit/f9278ab70cdff869e81082016fd848e98ba184de (0058) upstream: https://github.com/silnrsi/graphite/commit/98266d29bf0c9ebc5553630385abd868767f160b (0061) upstream_graphite2: released (1.3.5-1) precise_graphite2: ignored (reached end-of-life) precise/esm_graphite2: DNE (precise was needs-triage) trusty_graphite2: released (1.2.4-1ubuntu1.1) trusty/esm_graphite2: released (1.2.4-1ubuntu1.1) vivid/stable-phone-overlay_graphite2: ignored (reached end-of-life) vivid/ubuntu-core_graphite2: DNE wily_graphite2: released (1.2.4-3ubuntu1.1) xenial_graphite2: released (1.3.5-1ubuntu1) esm-infra/xenial_graphite2: released (1.3.5-1ubuntu1) yakkety_graphite2: released (1.3.5-1ubuntu1) zesty_graphite2: released (1.3.5-1ubuntu1) devel_graphite2: released (1.3.5-1ubuntu1)