CVE-2016-1523

Description

The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.341

Associated Vulnerability

VulnerabilityOS Platform
Update for Mozilla Thunderbird (38.6.0)Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.1.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.1.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.0.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.0.5Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.1.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.2.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.2.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.0.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.0.5Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.1.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.2.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.2.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.3.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.4.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.3.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.4.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.5.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.5.1Windows
Vulnerabilities CVE-2016-1521,CVE-2016-1522,CVE-2016-1523,CVE-2016-1526 are affected in Mozilla Firefox (x64) 38.5.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.6.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.5.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.5.1Windows
Vulnerabilities CVE-2016-1521,CVE-2016-1522,CVE-2016-1523,CVE-2016-1526 are affected in Mozilla_Firefox 38.5.2Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.6.0Windows
Multiple Vulnerabilities are affected in Firefox ESR for Mac 38.0Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 38.0Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 38.1.0Mac
Multiple Vulnerabilities are affected in Firefox ESR for Mac 38.1.0Mac
Multiple Vulnerabilities are affected in Firefox ESR for Mac 38.0.1Mac
Multiple Vulnerabilities are affected in Firefox ESR for Mac 38.0.5Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 38.0.1Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 38.0.5Mac
Multiple Vulnerabilities are affected in Firefox ESR for Mac 38.2.0Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 38.2.0Mac
Multiple Vulnerabilities are affected in Firefox ESR for Mac 38.1.1Mac
Multiple Vulnerabilities are affected in Firefox ESR for Mac 38.2.1Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 38.1.1Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 38.2.1Mac
Multiple Vulnerabilities are affected in Firefox ESR for Mac 38.3.0Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 38.3.0Mac
Multiple Vulnerabilities are affected in Firefox ESR for Mac 38.4.0Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 38.4.0Mac
Multiple Vulnerabilities are affected in Firefox ESR for Mac 38.5.0Mac
Multiple Vulnerabilities are affected in Firefox ESR for Mac 38.5.1Mac
Vulnerabilities CVE-2016-1523,CVE-2016-2804 are affected in Firefox ESR for Mac 38.5.2Mac
Multiple Vulnerabilities are affected in Firefox ESR for Mac 38.6.0Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 38.5.0Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 38.5.1Mac
Vulnerabilities CVE-2016-1523,CVE-2016-2804 are affected in Mozilla Firefox for Mac 38.5.2Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 38.6.0Mac
Vulnerabilities CVE-2016-1523 are affected in Mozilla Thunderbird for Mac 38.5.1Mac
Vulnerabilities CVE-2016-1969,CVE-2016-1523 are fixed in Mozilla Firefox For Mac 38.6.1Mac
Font rendering engine for Complex Scripts (USN-2902-1) libgraphite2-3_1.2.4-1ubuntu1.1_i386.debLinux
Font rendering engine for Complex Scripts (USN-2902-1) libgraphite2-3_1.2.4-1ubuntu1.1_amd64.debLinux
Font rendering engine for Complex Scripts (USN-2902-1) libgraphite2-3_1.2.4-3ubuntu1.1_i386.debLinux
Font rendering engine for Complex Scripts (USN-2902-1) libgraphite2-3_1.2.4-3ubuntu1.1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-2904-1) thunderbird_38.6.0+build1-0ubuntu0.12.04.1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-2904-1) thunderbird_38.6.0+build1-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-2904-1) thunderbird_38.6.0+build1-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-2904-1) thunderbird_38.6.0+build1-0ubuntu0.15.10.1_i386.debLinux
SUSE-SU-2016:0779-1(SUSE Linux Enterprise Desktop 12 ) graphite2-debuginfo-1.3.1-6.1.x86_64.rpmLinux
SUSE-SU-2016:0779-1(SUSE Linux Enterprise Desktop 12 ) graphite2-debugsource-1.3.1-6.1.x86_64.rpmLinux
SUSE-SU-2016:0779-1(SUSE Linux Enterprise Desktop 12 ) libgraphite2-3-1.3.1-6.1.x86_64.rpmLinux
SUSE-SU-2016:0779-1(SUSE Linux Enterprise Desktop 12 ) libgraphite2-3-32bit-1.3.1-6.1.x86_64.rpmLinux
SUSE-SU-2016:0779-1(SUSE Linux Enterprise Desktop 12 ) libgraphite2-3-debuginfo-1.3.1-6.1.x86_64.rpmLinux
SUSE-SU-2016:0779-1(SUSE Linux Enterprise Desktop 12 ) libgraphite2-3-debuginfo-32bit-1.3.1-6.1.x86_64.rpmLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-303211Update for Mozilla Thunderbird (38.6.0)
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611807Mozilla Thunderbird For Mac (142.0)
PATCH-612783Mozilla Firefox For Mac (145.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234