PT-2016-1130 · Google+6 · Google Chrome+6
Kcc
·
Published
2016-01-15
·
Updated
2017-08-31
·
CVE-2016-2052
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
HarfBuzz versions prior to 1.0.6
Google Chrome versions prior to 48.0.2564.82
Description
The issue is related to multiple unspecified vulnerabilities in the HarfBuzz library and Google Chrome browser, caused by errors in the code. Exploitation of these vulnerabilities may allow a remote attacker to cause a denial of service or possibly have other impact via crafted data. A specific example of the issue is a buffer over-read resulting from an inverted length check in
hb-ot-font.cc.Recommendations
For HarfBuzz versions prior to 1.0.6, update to version 1.0.6 or later to resolve the issue.
For Google Chrome versions prior to 48.0.2564.82, update to version 48.0.2564.82 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Harfbuzz
Opera
Red Hat
Suse
Ubuntu