8.8
CVSSv3

CVE-2016-1521

Published: 13/02/2016 Updated: 01/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox prior to 43.0 and Firefox ESR 38.x prior to 38.6.1, does not validate a certain skip operation, which allows remote malicious users to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

debian debian linux 7.0

sil graphite2

mozilla firefox esr 38.2.1

mozilla firefox esr 38.2.0

mozilla firefox esr 38.4.0

mozilla firefox esr 38.3.0

mozilla firefox

mozilla firefox esr 38.6.0

mozilla firefox esr 38.5.2

mozilla firefox esr 38.1.1

mozilla firefox esr 38.1.0

mozilla firefox esr 38.5.1

mozilla firefox esr 38.5.0

mozilla firefox esr 38.0.5

mozilla firefox esr 38.0.1

mozilla thunderbird

fedoraproject fedora 23

fedoraproject fedora 22

Vendor Advisories

graphite2 could be made to crash or run programs as your login if it opened a specially crafted font ...
Multiple vulnerabilities have been found in the Graphite font rendering engine which might result in denial of service or the execution of arbitrary code if a malformed font file is processed For the oldstable distribution (wheezy), these problems have been fixed in version 135-1~deb7u1 For the stable distribution (jessie), these problems have ...
Several vulnerabilities were discovered in Graphite2 An attacker able to trick an unsuspecting user into opening specially crafted font files in an application using Graphite2 could exploit these flaws to cause the application to crash or, potentially, execute arbitrary code with the privileges of the application ...
A vulnerability has been discovered in Graphite2 An attacker able to trick an unsuspecting user into opening specially crafted font files in an application using Graphite2 could exploit these flaws to cause the application to crash or, potentially, execute arbitrary code with the privileges of the application ...

Recent Articles

It's 2016 and a font file can own your computer
The Register • Richard Chirgwin • 09 Feb 2016

Libgraphite font library buggy and vulnerable in Firefox, Thunderbird, WordPad and more says Talos

Updated Cisco-owned Talos has announced a bunch of font library bugs present in apps running on Windows and Linux, affecting client and-server-side machines. The problem is in the Libgraphite library, and means that applications using the library to load .TTF font files can inherit its vulnerabilities. All that's needed for a successful exploit, Talos writes, is that the user be tricked into running a Graphite-enabled application rendering a page with a maliciously crafted font. Since Libgraphit...