PublicDateAtUSN: 2016-02-08 Candidate: CVE-2016-1522 PublicDate: 2016-02-13 02:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1522 http://www.talosintel.com/reports/TALOS-2016-0057/ http://www.talosintel.com/reports/TALOS-2016-0060/ http://blog.talosintel.com/2016/02/vulnerability-spotlight-libgraphite.html https://ubuntu.com/security/notices/USN-2902-1 Description: Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Yves Younan Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_graphite2: upstream: https://github.com/silnrsi/graphite/commit/4e232ad3697bd0121fd3cbfd8c3d9e2617fce1b8 (0057) upstream: https://github.com/silnrsi/graphite/commit/a94bbf1a651b13ecfaf9a774a841d36964c25929 (0060) upstream_graphite2: released (1.3.5-1) precise_graphite2: ignored (reached end-of-life) precise/esm_graphite2: DNE (precise was needs-triage) trusty_graphite2: released (1.2.4-1ubuntu1.1) trusty/esm_graphite2: released (1.2.4-1ubuntu1.1) vivid/stable-phone-overlay_graphite2: ignored (reached end-of-life) vivid/ubuntu-core_graphite2: DNE wily_graphite2: released (1.2.4-3ubuntu1.1) xenial_graphite2: released (1.3.5-1ubuntu1) esm-infra/xenial_graphite2: released (1.3.5-1ubuntu1) yakkety_graphite2: released (1.3.5-1ubuntu1) zesty_graphite2: released (1.3.5-1ubuntu1) devel_graphite2: released (1.3.5-1ubuntu1)