platform/fonts/shaping/HarfBuzzShaper.cpp in Blink, as used in Google Chrome before 43.0.2357.65, does not initialize a certain width field, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Unicode text.
https://src.chromium.org/viewvc/blink?revision=194541&view=revision
https://security.gentoo.org/glsa/201506-04
https://code.google.com/p/chromium/issues/detail?id=476647
http://www.securitytracker.com/id/1032375
http://www.securityfocus.com/bid/74723
http://www.debian.org/security/2015/dsa-3267
http://lists.opensuse.org/opensuse-updates/2015-11/msg00015.html
http://lists.opensuse.org/opensuse-updates/2015-05/msg00091.html