CVE-2016-2052Improper Restriction of Operations within the Bounds of a Memory Buffer in Harfbuzz

Severity
7.6HIGHNVD
EPSS
0.4%
top 38.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 25
Latest updateMay 17

Description

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:HExploitability: 2.8 | Impact: 4.7

Affected Packages5 packages

NVDgoogle/chrome47.0.2526.106
debiandebian/harfbuzz< harfbuzz 1.2.6-1 (bookworm)
Debianharfbuzz_project/harfbuzz< 1.2.6-1+3
Ubuntuharfbuzz_project/harfbuzz< 0.9.27-1ubuntu1.1+1

🔴Vulnerability Details

6
GHSA
GHSA-vx72-qhm5-54jj: Multiple unspecified vulnerabilities in HarfBuzz before 12022-05-17
GHSA
GHSA-8w8v-wf57-7pwq: hb-ot-layout-gpos-table2022-05-14
OSV
harfbuzz vulnerabilities2016-08-24
OSV
CVE-2015-8947: hb-ot-layout-gpos-table2016-07-19
OSV
oxide-qt vulnerabilities2016-01-27

📋Vendor Advisories

6
Ubuntu
HarfBuzz vulnerabilities2016-08-24
Ubuntu
Oxide vulnerabilities2016-01-27
Red Hat
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.62016-01-24
Red Hat
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.62016-01-24
Debian
CVE-2016-2052: harfbuzz - Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google...2016

💬Community

4
Bugzilla
CVE-2015-8947 CVE-2016-2052 harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [epel-7]2016-07-21
Bugzilla
CVE-2015-8947 CVE-2016-2052 mingw-harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [fedora-all]2016-07-21
Bugzilla
CVE-2015-8947 CVE-2016-2052 harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [fedora-all]2016-07-21
Bugzilla
CVE-2016-2052 CVE-2015-8947 chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.62016-01-25
CVE-2016-2052 — Debian Harfbuzz vulnerability | cvebase