CVE-2017-7772 (NVD)

2019-04-12

Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.

Products Firefox, Graphite2
Type Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119)
First patch - None (likely due to unavailable code)
Links https://www.mozilla.org/en-US/security/advisories/mfsa2017-15/