PublicDateAtUSN: 2016-02-08 Candidate: CVE-2016-1526 PublicDate: 2016-02-13 02:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1526 http://blog.talosintel.com/2016/02/vulnerability-spotlight-libgraphite.html https://ubuntu.com/security/notices/USN-2902-1 Description: The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font. Ubuntu-Description: Notes: sbeattie> probably DoS issue, CVE is referenced in blog post, but doesn't show up in detailed reports under http://www.talosintel.com/vulnerability-reports/ Bugs: Priority: low Discovered-by: Yves Younan Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H [8.1 HIGH] Patches_graphite2: upstream_graphite2: released (1.3.5-1) precise_graphite2: ignored (reached end-of-life) precise/esm_graphite2: DNE (precise was needed) trusty_graphite2: released (1.2.4-1ubuntu1.1) trusty/esm_graphite2: released (1.2.4-1ubuntu1.1) vivid/stable-phone-overlay_graphite2: ignored (reached end-of-life) vivid/ubuntu-core_graphite2: DNE wily_graphite2: released (1.2.4-3ubuntu1.1) xenial_graphite2: released (1.3.5-1ubuntu1) esm-infra/xenial_graphite2: released (1.3.5-1ubuntu1) yakkety_graphite2: released (1.3.5-1ubuntu1) zesty_graphite2: released (1.3.5-1ubuntu1) devel_graphite2: released (1.3.5-1ubuntu1)