CVE-2016-1523
published 2016-02-13CVE-2016-1523: The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1…
PriorityP423medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
2.32%
81.5th percentile
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | graphite2 | < graphite2 1.3.5-1 (bookworm) | graphite2 1.3.5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | thunderbird | <= 38.5.1 | — |
| mozilla | thunderbird | >= 0 < 1:38.6.0+build1-0ubuntu0.14.04.1 | 1:38.6.0+build1-0ubuntu0.14.04.1 |
| sil | graphite2 | — | — |
| sil | graphite2 | >= 0 < 1.3.5-1 | 1.3.5-1 |
| sil | graphite2 | >= 0 < 1.3.5-1 | 1.3.5-1 |
| sil | graphite2 | >= 0 < 1.3.5-1 | 1.3.5-1 |
| sil | graphite2 | >= 0 < 1.3.5-1 | 1.3.5-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2016-03-08·CVSS 5.9
CVE-2015-7575 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Karthikeyan Bhargavan and Gaetan Leurent discovered that NSS incorrectly
allowed MD5 to be used for TLS 1.2 connections. If a remote attacker were
able to perform a machine-in-the-middle attack, this flaw could be exploited to
view sensitive information. (CVE-2015-7575)
Yves Younan discovered that graphite2 incorrectly handled certain malformed
fonts. If a user were tricked into opening a specially crafted website in a
browsing context, an attacker could potentially exploit this to cause a
denial of service via application crash, or execute arbitary code with the
privileges of the user invoking Thunderbird. (CVE-2016-1523)
Bob Clary, Christian Holler, Nils Ohlmeier, Gary Kwong, Jesse Ruderman
Ubuntu
graphite2 vulnerabilities
vendor_ubuntu·2016-02-17
CVE-2016-1521 graphite2 vulnerabilities
Title: graphite2 vulnerabilities
Summary: graphite2 could be made to crash or run programs as your login if it
opened a specially crafted font.
Yves Younan discovered that graphite2 incorrectly handled certain malformed
fonts. If a user or automated system were tricked into opening a specially-
crafted font file, a remote attacker could use this issue to cause
graphite2 to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart applications using
graphite2, such as LibreOffice, to make all the necessary changes.
Red Hat
graphite2: Heap-based buffer overflow in context item handling functionality
vendor_redhat·2016-02-05·CVSS 6.5
CVE-2016-1523 [MEDIUM] CWE-122 graphite2: Heap-based buffer overflow in context item handling functionality
graphite2: Heap-based buffer overflow in context item handling functionality
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
A vulnerability has been discovered in Graphite2. An attacker able to trick an unsuspecting user into opening specially crafted font files in an application using Graphite2 could exploit these flaws to cause the application to crash or, potentially, execute arbitrary code with the privileges of the application.
Debian
CVE-2016-1523: graphite2 - The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1....
vendor_debian·2016·CVSS 6.5
CVE-2016-1523 [MEDIUM] CVE-2016-1523: graphite2 - The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1....
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
Scope: local
bookworm: resolved (fixed in 1.3.5-1)
bullseye: resolved (fixed in 1.3.5-1)
forky: resolved (fixed in 1.3.5-1)
sid: resolved (fixed in 1.3.5-1)
trixie: resolved (fixed in 1.3.5-1)
GHSA
GHSA-996f-83x4-9fpc: The SillMap::readFace function in FeatureMap
ghsa_unreviewed·2022-05-17
CVE-2016-1523 [MEDIUM] GHSA-996f-83x4-9fpc: The SillMap::readFace function in FeatureMap
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
OSV
thunderbird vulnerabilities
osv·2016-03-08·CVSS 5.9
CVE-2015-7575 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Karthikeyan Bhargavan and Gaetan Leurent discovered that NSS incorrectly
allowed MD5 to be used for TLS 1.2 connections. If a remote attacker were
able to perform a machine-in-the-middle attack, this flaw could be exploited to
view sensitive information. (CVE-2015-7575)
Yves Younan discovered that graphite2 incorrectly handled certain malformed
fonts. If a user were tricked into opening a specially crafted website in a
browsing context, an attacker could potentially exploit this to cause a
denial of service via application crash, or execute arbitary code with the
privileges of the user invoking Thunderbird. (CVE-2016-1523)
Bob Clary, Christian Holler, Nils Ohlmeier, Gary Kwong, Jesse Ruderman,
Carsten Book, and Randell Jesup discovered multiple memory safety
OSV
CVE-2016-1523: The SillMap::readFace function in FeatureMap
osv·2016-02-13·CVSS 6.5
CVE-2016-1523 [MEDIUM] CVE-2016-1523: The SillMap::readFace function in FeatureMap
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Libgraphite Font Processing Vulnerabilities
blogs_talos·2016-02-05·CVSS 8.8
[HIGH] Vulnerability Spotlight: Libgraphite Font Processing Vulnerabilities
## Vulnerability Spotlight: Libgraphite Font Processing Vulnerabilities
Vulnerabilities Discovered by Yves Younan of Cisco Talos.
Talos is releasing an advisory for four vulnerabilities that have been found within the Libgraphite library, which is used for font processing in Linux, Firefox, LibreOffice, and other major applications. The most severe vulnerability results from an out-of-bounds read which the attacker can use to achieve arbitrary code execution. A second vulnerability is an exploitable heap overflow. Finally, the last two vulnerabilities result in denial of service situations. To exploit these vulnerabilities, an attacker simply needs the user to run a Graphite-enabled application that renders a page using a specially crafted font that triggers one of these vulnerabilities.
Talos
Vulnerability Spotlight: Libgraphite Font Processing Vulnerabilities
blogs_talos·2016-02-05·CVSS 8.8
[HIGH] Vulnerability Spotlight: Libgraphite Font Processing Vulnerabilities
Vulnerabilities Discovered by Yves Younan of Cisco Talos.
Talos is releasing an advisory for four vulnerabilities that have been found within the Libgraphite library, which is used for font processing in Linux, Firefox, LibreOffice, and other major applications. The most severe vulnerability results from an out-of-bounds read which the attacker can use to achieve arbitrary code execution. A second vulnerability is an exploitable heap overflow. Finally, the last two vulnerabilities result in denial of service situations. To exploit these vulnerabilities, an attacker simply needs the user to run a Graphite-enabled application that renders a page using a specially crafted font that triggers one of these vulnerabilities. Since Mozilla Firefox versions 11-42 directly support Graphite, the atta
Bugzilla
CVE-2016-1523 graphite2: Heap-based buffer overflow in context item handling functionality [fedora-all]
bugzilla·2016-02-09·CVSS 6.5
CVE-2016-1523 [MEDIUM] CVE-2016-1523 graphite2: Heap-based buffer overflow in context item handling functionality [fedora-all]
CVE-2016-1523 graphite2: Heap-based buffer overflow in context item handling functionality [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2016-1523 graphite2: Heap-based buffer overflow in context item handling functionality
bugzilla·2016-02-09·CVSS 6.5
CVE-2016-1523 [MEDIUM] CVE-2016-1523 graphite2: Heap-based buffer overflow in context item handling functionality
CVE-2016-1523 graphite2: Heap-based buffer overflow in context item handling functionality
An exploitable heap-based buffer overflow was found in the context item handling functionality of Libgraphite. A specially crafted font can cause a buffer overflow resulting in potential code execution. An attacker can provide a malicious font to trigger this vulnerability.
External Reference:
http://www.talosintel.com/reports/TALOS-2016-0059/
Discussion:
Created graphite2 tracking bugs for this issue:
Affects: fedora-all [bug 1305814]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:0197 https://rhn.redhat.com/errata/RHSA-2016-0197.html
---
This issue has been addressed in the follo
http://blog.talosintel.com/2016/02/vulnerability-spotlight-libgraphite.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177520.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/184623.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00053.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00055.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00058.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00088.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0258.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0594.htmlhttp://www.debian.org/security/2016/dsa-3477http://www.debian.org/security/2016/dsa-3479http://www.debian.org/security/2016/dsa-3491http://www.mozilla.org/security/announce/2016/mfsa2016-14.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/82991http://www.securitytracker.com/id/1035017http://www.ubuntu.com/usn/USN-2902-1http://www.ubuntu.com/usn/USN-2904-1https://bugzilla.mozilla.org/show_bug.cgi?id=1246093https://security.gentoo.org/glsa/201605-06https://security.gentoo.org/glsa/201701-35https://security.gentoo.org/glsa/201701-63http://blog.talosintel.com/2016/02/vulnerability-spotlight-libgraphite.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177520.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/184623.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00053.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00055.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00058.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00088.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0258.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0594.htmlhttp://www.debian.org/security/2016/dsa-3477http://www.debian.org/security/2016/dsa-3479http://www.debian.org/security/2016/dsa-3491http://www.mozilla.org/security/announce/2016/mfsa2016-14.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/82991http://www.securitytracker.com/id/1035017http://www.ubuntu.com/usn/USN-2902-1http://www.ubuntu.com/usn/USN-2904-1https://bugzilla.mozilla.org/show_bug.cgi?id=1246093https://security.gentoo.org/glsa/201605-06https://security.gentoo.org/glsa/201701-35https://security.gentoo.org/glsa/201701-63
2016-02-13
Published