ubuntu · CVE-2016-2797

Quick triage

Priority: medium Published: 2016-03-08 00:00:00 UTC Updated: 2025-08-25 21:58:42 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-2797 medium priority: Ubuntu including 3 source packages (firefox, graphite2, thunderbird), 21 status rows across 7 suites (precise, trusty, upstream, wily, xenial, yakkety, zesty): released 17, not-affected 3, ignored 1.

Description:

The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2801.

cvelogic Threat Intelligence