CVE-2016-2052

Published on: 01/25/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:15 PM UTC

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Certain versions of Chrome from Google contain the following vulnerability:

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

  • CVE-2016-2052 has been assigned by [email protected] to track the vulnerability - currently rated as HIGH severity.

CVSS3 Score: 7.6 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE REQUIRED
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED LOW LOW HIGH

CVSS2 Score: 6.8 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK MEDIUM NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
PARTIAL PARTIAL PARTIAL

CVE References

Description Tags Link
HarfBuzz: Multiple vulnerabilities (GLSA 201701-76) — Gentoo Security security.gentoo.org
text/html
URL Logo GENTOO GLSA-201701-76
HarfBuzz CVE-2016-2052 Multiple Security Vulnerabilities cve.report (archive)
text/html
URL Logo BID 81812
Chrome Releases: Stable Channel Update Vendor Advisory
googlechromereleases.blogspot.com
text/html
URL Logo CONFIRM googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.html
Issue 579625 - chromium - Tracking bug for internal fixes: Chrome M48, release 0 - Monorail code.google.com
text/html
URL Logo CONFIRM code.google.com/p/chromium/issues/detail?id=579625
fuzzing harfbuzz · Issue #139 · behdad/harfbuzz · GitHub github.com
text/x-c
CONFIRM github.com/behdad/harfbuzz/issues/139#issuecomment-148289957
544270 - chromium - An open-source project to help move the web forward. - Monorail code.google.com
text/html
URL Logo CONFIRM code.google.com/p/chromium/issues/detail?id=544270
USN-2877-1: Oxide vulnerabilities | Ubuntu www.ubuntu.com
text/html
URL Logo UBUNTU USN-2877-1
[ot-font] Fix hmtx wrong table length check · harfbuzz/[email protected] · GitHub github.com
text/html
URL Logo CONFIRM github.com/behdad/harfbuzz/commit/63ef0b41dc48d6112d1918c1b1de9de8ea90adb5
Google Chrome Multiple Bugs Let Remote Users Obtain Information, Bypass Security Restrictions, Spoof URLs, and Execute Arbitrary Code - SecurityTracker www.securitytracker.com
text/html
URL Logo SECTRACK 1034801
USN-3067-1: HarfBuzz vulnerabilities | Ubuntu www.ubuntu.com
text/html
URL Logo UBUNTU USN-3067-1
Red Hat Customer Portal web.archive.org
text/html
Inactive LinkNot Archived
URL Logo REDHAT RHSA-2016:0072
openSUSE-SU-2016:2082-1: moderate: Security update for harfbuzz lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:2082

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationGoogleChromeAllAllAllAll
ApplicationHarfbuzz ProjectHarfbuzzAllAllAllAll
  • cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:harfbuzz_project:harfbuzz:*:*:*:*:*:*:*:*: