Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
{ "urgency": "not yet assigned" }