CVE-2016-2052
published 2016-01-25CVE-2016-2052: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or…
PriorityP428high7.6CVSS 3.0
AVNACLPRNUIRSUCLILAH
EPSS
0.96%
57.5th percentile
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | harfbuzz | < harfbuzz 1.2.6-1 (bookworm) | harfbuzz 1.2.6-1 (bookworm) |
| chrome | <= 47.0.2526.106 | — | |
| harfbuzz_project | harfbuzz | <= 1.0.5 | — |
| harfbuzz_project | harfbuzz | <= 1.0.4 | — |
| harfbuzz_project | harfbuzz | >= 0 < 1.2.6-1 | 1.2.6-1 |
| harfbuzz_project | harfbuzz | >= 0 < 1.2.6-1 | 1.2.6-1 |
| harfbuzz_project | harfbuzz | >= 0 < 1.2.6-1 | 1.2.6-1 |
| harfbuzz_project | harfbuzz | >= 0 < 1.2.6-1 | 1.2.6-1 |
| harfbuzz_project | harfbuzz | >= 0 < 0.9.27-1ubuntu1.1 | 0.9.27-1ubuntu1.1 |
| harfbuzz_project | harfbuzz | >= 0 < 1.0.1-1ubuntu0.1 | 1.0.1-1ubuntu0.1 |
CVSS provenance
nvdv3.07.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.6HIGH
vendor_debian7.6HIGH
vendor_redhat7.6HIGH
vendor_ubuntu7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
HarfBuzz vulnerabilities
vendor_ubuntu·2016-08-24·CVSS 7.6
CVE-2015-8947 [HIGH] HarfBuzz vulnerabilities
Title: HarfBuzz vulnerabilities
Summary: HarfBuzz could be made to crash or run programs as your login if it
processed specially crafted data.
Kostya Serebryany discovered that HarfBuzz incorrectly handled memory. A
remote attacker could use this issue to cause HarfBuzz to crash, resulting
in a denial of service, or possibly execute arbitrary code. (CVE-2015-8947)
It was discovered that HarfBuzz incorrectly handled certain length checks.
A remote attacker could use this issue to cause HarfBuzz to crash,
resulting in a denial of service, or possibly execute arbitrary code.
This issue only applied to Ubuntu 16.04 LTS. (CVE-2016-2052)
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-01-27·CVSS 7.6
CVE-2016-1612 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A bad cast was discovered in V8. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service via renderer crash or execute arbitrary code
with the privileges of the sandboxed render process. (CVE-2016-1612)
An issue was discovered when initializing the UnacceleratedImageBufferSurface
class in Blink. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to obtain sensitive
information. (CVE-2016-1614)
An issue was discovered with the CSP implementation in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to de
Red Hat
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
vendor_redhat·2016-01-24·CVSS 7.6
CVE-2015-8947 [HIGH] chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052.
Package: harfbuzz (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
vendor_redhat·2016-01-24·CVSS 7.6
CVE-2016-2052 [HIGH] chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.
Package: harfbuzz (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-2052: harfbuzz - Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google...
vendor_debian·2016·CVSS 7.6
CVE-2016-2052 [HIGH] CVE-2016-2052: harfbuzz - Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google...
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.
Scope: local
bookworm: resolved (fixed in 1.2.6-1)
bullseye: resolved (fixed in 1.2.6-1)
forky: resolved (fixed in 1.2.6-1)
sid: resolved (fixed in 1.2.6-1)
trixie: resolved (fixed in 1.2.6-1)
Debian
CVE-2015-8947: harfbuzz - hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to c...
vendor_debian·2015·CVSS 7.6
CVE-2015-8947 [HIGH] CVE-2015-8947: harfbuzz - hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to c...
hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052.
Scope: local
bookworm: resolved (fixed in 1.2.6-1)
bullseye: resolved (fixed in 1.2.6-1)
forky: resolved (fixed in 1.2.6-1)
sid: resolved (fixed in 1.2.6-1)
trixie: resolved (fixed in 1.2.6-1)
GHSA
GHSA-vx72-qhm5-54jj: Multiple unspecified vulnerabilities in HarfBuzz before 1
ghsa_unreviewed·2022-05-17·CVSS 7.6
CVE-2016-2052 [HIGH] GHSA-vx72-qhm5-54jj: Multiple unspecified vulnerabilities in HarfBuzz before 1
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.
GHSA
GHSA-8w8v-wf57-7pwq: hb-ot-layout-gpos-table
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2015-8947 [HIGH] CWE-119 GHSA-8w8v-wf57-7pwq: hb-ot-layout-gpos-table
hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052.
OSV
harfbuzz vulnerabilities
osv·2016-08-24·CVSS 7.6
CVE-2015-8947 [HIGH] harfbuzz vulnerabilities
harfbuzz vulnerabilities
Kostya Serebryany discovered that HarfBuzz incorrectly handled memory. A
remote attacker could use this issue to cause HarfBuzz to crash, resulting
in a denial of service, or possibly execute arbitrary code. (CVE-2015-8947)
It was discovered that HarfBuzz incorrectly handled certain length checks.
A remote attacker could use this issue to cause HarfBuzz to crash,
resulting in a denial of service, or possibly execute arbitrary code.
This issue only applied to Ubuntu 16.04 LTS. (CVE-2016-2052)
OSV
CVE-2015-8947: hb-ot-layout-gpos-table
osv·2016-07-19·CVSS 7.6
CVE-2015-8947 [HIGH] CVE-2015-8947: hb-ot-layout-gpos-table
hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052.
OSV
oxide-qt vulnerabilities
osv·2016-01-27·CVSS 7.6
CVE-2016-1612 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A bad cast was discovered in V8. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service via renderer crash or execute arbitrary code
with the privileges of the sandboxed render process. (CVE-2016-1612)
An issue was discovered when initializing the UnacceleratedImageBufferSurface
class in Blink. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to obtain sensitive
information. (CVE-2016-1614)
An issue was discovered with the CSP implementation in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to determine whether specific HSTS sites had been
visited by rea
OSV
CVE-2016-2052: Multiple unspecified vulnerabilities in HarfBuzz before 1
osv·2016-01-25·CVSS 7.6
CVE-2016-2052 [HIGH] CVE-2016-2052: Multiple unspecified vulnerabilities in HarfBuzz before 1
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8947 CVE-2016-2052 harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [epel-7]
bugzilla·2016-07-21·CVSS 7.6
CVE-2015-8947 [HIGH] CVE-2015-8947 CVE-2016-2052 harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [epel-7]
CVE-2015-8947 CVE-2016-2052 harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[b
Bugzilla
CVE-2015-8947 CVE-2016-2052 mingw-harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [fedora-all]
bugzilla·2016-07-21·CVSS 7.6
CVE-2015-8947 [HIGH] CVE-2015-8947 CVE-2016-2052 mingw-harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [fedora-all]
CVE-2015-8947 CVE-2016-2052 mingw-harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
Bugzilla
CVE-2015-8947 CVE-2016-2052 harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [fedora-all]
bugzilla·2016-07-21·CVSS 7.6
CVE-2015-8947 [HIGH] CVE-2015-8947 CVE-2016-2052 harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [fedora-all]
CVE-2015-8947 CVE-2016-2052 harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2016-2052 CVE-2015-8947 chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
bugzilla·2016-01-25·CVSS 7.6
CVE-2016-2052 [HIGH] CVE-2016-2052 CVE-2015-8947 chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
CVE-2016-2052 CVE-2015-8947 chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 were found, as used in Google Chrome before 48.0.2564.82, allowing attackers to cause a denial of service or possibly have other impact via unknown vectors.
Upstream tracking bug:
https://code.google.com/p/chromium/issues/detail?id=544270
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0072 https://rhn.redhat.com/errata/RHSA-2016-0072.html
---
This CVE was assigned to "Update harfbuzz to 1.0.6" in chromium browser. (As referenced by the comment #0 above). When investigating this issue it seems all the issues fixed in 1.0.5 and subseque
http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.htmlhttp://lists.opensuse.org/opensuse-updates/2016-08/msg00070.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0072.htmlhttp://www.securityfocus.com/bid/81812http://www.securitytracker.com/id/1034801http://www.ubuntu.com/usn/USN-2877-1http://www.ubuntu.com/usn/USN-3067-1https://code.google.com/p/chromium/issues/detail?id=544270https://code.google.com/p/chromium/issues/detail?id=579625https://github.com/behdad/harfbuzz/commit/63ef0b41dc48d6112d1918c1b1de9de8ea90adb5https://github.com/behdad/harfbuzz/issues/139#issuecomment-148289957https://security.gentoo.org/glsa/201701-76http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.htmlhttp://lists.opensuse.org/opensuse-updates/2016-08/msg00070.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0072.htmlhttp://www.securityfocus.com/bid/81812http://www.securitytracker.com/id/1034801http://www.ubuntu.com/usn/USN-2877-1http://www.ubuntu.com/usn/USN-3067-1https://code.google.com/p/chromium/issues/detail?id=544270https://code.google.com/p/chromium/issues/detail?id=579625https://github.com/behdad/harfbuzz/commit/63ef0b41dc48d6112d1918c1b1de9de8ea90adb5https://github.com/behdad/harfbuzz/issues/139#issuecomment-148289957https://security.gentoo.org/glsa/201701-76
2016-01-25
Published