CVE-2016-1523: Debian Linux

Medium severity, CVSS 6.5. EPSS: 2.3% chance of exploitation in the next 30 days.

The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Fedoraproject Fedora: version 22 only; version 23 only
  • Mozilla Firefox: version 38.0 only; version 38.0.1 only; version 38.0.5 only; version 38.1.0 only; version 38.1.1 only; version 38.2.0 only; …
  • Mozilla Thunderbird: up to and including 38.5.1
  • Sil GRAPHITE2: version 1.2.4 only

Published 2016-02-13. Last modified 2026-06-17.