Vulnerability Description
YoruFukurou (NightOwl) before 2.85 relies on support for emoji skin-tone modifiers even though this support is missing from the CoreText CTFramesetter API on OS X 10.9, which allows remote attackers to cause a denial of service (application crash) via a crafted emoji character sequence.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aki-Null | Yorufukurou | <= 2.84 |
| Apple | Mac Os X | 10.9 |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN94816361/995844/index.htmlThird Party Advisory
- http://jvn.jp/en/jp/JVN94816361/index.htmlThird Party Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000151Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/92609
- http://jvn.jp/en/jp/JVN94816361/995844/index.htmlThird Party Advisory
- http://jvn.jp/en/jp/JVN94816361/index.htmlThird Party Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000151Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/92609
FAQ
What is CVE-2016-4852?
CVE-2016-4852 is a vulnerability with a CVSS score of 6.5 (MEDIUM). YoruFukurou (NightOwl) before 2.85 relies on support for emoji skin-tone modifiers even though this support is missing from the CoreText CTFramesetter API on OS X 10.9, which allows remote attackers t...
How severe is CVE-2016-4852?
CVE-2016-4852 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-4852?
Check the references section above for vendor advisories and patch information. Affected products include: Aki-Null Yorufukurou, Apple Mac Os X.