CVE-2016-1969
published 2016-03-13CVE-2016-1969: The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a…
PriorityP335high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.67%
74.1th percentile
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| debian | firefox-esr | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| debian | graphite2 | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| mozilla | firefox | <= 44.0.2 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| sil | graphite2 | <= 1.3.5 | — |
| sil | graphite2 | >= 0 < 1.3.6-1 | 1.3.6-1 |
| sil | graphite2 | >= 0 < 1.3.6-1 | 1.3.6-1 |
| sil | graphite2 | >= 0 < 1.3.6-1 | 1.3.6-1 |
| sil | graphite2 | >= 0 < 1.3.6-1 | 1.3.6-1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mozilla: out-of-bounds write with malicious font in graphite2 (MFSA 2016-38)
vendor_redhat·2016-03-08·CVSS 8.8
CVE-2016-1969 [HIGH] CWE-787 mozilla: out-of-bounds write with malicious font in graphite2 (MFSA 2016-38)
mozilla: out-of-bounds write with malicious font in graphite2 (MFSA 2016-38)
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-1969: firefox - The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox befo...
vendor_debian·2016·CVSS 8.8
CVE-2016-1969 [HIGH] CVE-2016-1969: firefox - The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox befo...
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (fixed in 45.0-1)
GHSA
GHSA-29w8-qmxg-g64x: The setAttr function in Graphite 2 before 1
ghsa_unreviewed·2022-05-17
CVE-2016-1969 [HIGH] CWE-119 GHSA-29w8-qmxg-g64x: The setAttr function in Graphite 2 before 1
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.
OSV
CVE-2016-1969: The setAttr function in Graphite 2 before 1
osv·2016-03-13·CVSS 8.8
CVE-2016-1969 [HIGH] CVE-2016-1969: The setAttr function in Graphite 2 before 1
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5398 stored XSS in JBoss BPM suite business process editor
bugzilla·2016-07-20·CVSS 5.4
CVE-2016-5398 [MEDIUM] CVE-2016-5398 stored XSS in JBoss BPM suite business process editor
CVE-2016-5398 stored XSS in JBoss BPM suite business process editor
JBoss BPM Suite 6.3.0 is vulnerable to a stored XSS via business process
editor. Remote authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users, including admins.
Discussion:
Acknowledgments:
Name: Jeremy Choi (Red Hat Product Security Team)
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.3.3
Via RHSA-2016:1969 https://rhn.redhat.com/errata/RHSA-2016-1969.html
---
This issue has been addressed in the following products:
Red Hat JBoss BRMS 6.3.3
Via RHSA-2016:1968 https://rhn.redhat.com/errata/RHSA-2016-1968.html
Bugzilla
CVE-2016-1969 mozilla: out-of-bounds write with malicious font in graphite2 (MFSA 2016-38)
bugzilla·2016-03-14·CVSS 8.8
CVE-2016-1969 [HIGH] CVE-2016-1969 mozilla: out-of-bounds write with malicious font in graphite2 (MFSA 2016-38)
CVE-2016-1969 mozilla: out-of-bounds write with malicious font in graphite2 (MFSA 2016-38)
Security researcher James Clawson used the Address Sanitizer tool to discover an out-of-bounds write in the Graphite 2 library when loading a crafted Graphite font file. This results in a potentially exploitable crash.
External references:
https://www.mozilla.org/en-US/security/advisories/mfsa2016-38/
Discussion:
This security flaw was addressed in the following Firefox update:
https://rhn.redhat.com/errata/RHSA-2016-0197.html
http://www.mozilla.org/security/announce/2016/mfsa2016-38.htmlhttp://www.securitytracker.com/id/1035215https://bugzilla.mozilla.org/show_bug.cgi?id=1242322https://security.gentoo.org/glsa/201605-06http://www.mozilla.org/security/announce/2016/mfsa2016-38.htmlhttp://www.securitytracker.com/id/1035215https://bugzilla.mozilla.org/show_bug.cgi?id=1242322https://security.gentoo.org/glsa/201605-06
2016-03-13
Published