CVE-2015-8947

Published: 19 July 2016

hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052.

Priority

Medium

CVSS 3 base score: 7.6

Status

Package Release Status
harfbuzz
Launchpad, Ubuntu, Debian
Upstream
Released (1.2.6-1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (1.0.1-1ubuntu0.1)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (0.9.27-1ubuntu1.1)
Patches:
Upstream: https://cgit.freedesktop.org/harfbuzz/commit/?id=f96664974774bfeb237a7274f512f64aaafb201e