Red Hat Bugzilla – Bug 1317560
CVE-2016-1969 mozilla: out-of-bounds write with malicious font in graphite2 (MFSA 2016-38)
Last modified: 2016-11-08 11:28:07 EST
Security researcher James Clawson used the Address Sanitizer tool to discover an out-of-bounds write in the Graphite 2 library when loading a crafted Graphite font file. This results in a potentially exploitable crash. External references: https://www.mozilla.org/en-US/security/advisories/mfsa2016-38/
This security flaw was addressed in the following Firefox update: https://rhn.redhat.com/errata/RHSA-2016-0197.html