PT-2016-1130 · Google+6 · Google Chrome+6

Kcc

·

Published

2016-01-15

·

Updated

2017-08-31

·

CVE-2016-2052

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions HarfBuzz versions prior to 1.0.6 Google Chrome versions prior to 48.0.2564.82
Description The issue is related to multiple unspecified vulnerabilities in the HarfBuzz library and Google Chrome browser, caused by errors in the code. Exploitation of these vulnerabilities may allow a remote attacker to cause a denial of service or possibly have other impact via crafted data. A specific example of the issue is a buffer over-read resulting from an inverted length check in hb-ot-font.cc.
Recommendations For HarfBuzz versions prior to 1.0.6, update to version 1.0.6 or later to resolve the issue. For Google Chrome versions prior to 48.0.2564.82, update to version 48.0.2564.82 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1029
BDU:2016-00389
CVE-2016-2052
MGASA-2016-0264
RHSA-2016:0072
RHSA-2016_0072
SUSE-SU-2017:1821-1
SUSE-SU-2017:2315-1
USN-2877-1
USN-3067-1

Affected Products

Alt Linux
Google Chrome
Harfbuzz
Opera
Red Hat
Suse
Ubuntu