PT-2016-1192 · Opera+4 · Opera+5

Publicado

2016-02-09

·

Atualizado

2024-06-15

·

CVE-2016-1626

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenJPEG versions prior to 48.0.2564.109 Google Chrome versions prior to 48.0.2564.109 PDFium versions prior to 48.0.2564.109 Opera versions prior to 48.0.2564.109
Description The issue is related to the opj pi update decode poc function in pi.c in OpenJPEG, which is used in PDFium in Google Chrome and Opera. This function miscalculates a certain layer index value, allowing remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document. The vulnerability can be exploited by a specially crafted PDF document, leading to a denial of service.
Recommendations For Google Chrome versions prior to 48.0.2564.109, update to version 48.0.2564.109 or later. For Opera versions prior to 48.0.2564.109, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the opj pi update decode poc function in pi.c until a patch is available. Restrict access to PDF documents from untrusted sources to minimize the risk of exploitation.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1098
BDU:2016-00453
CVE-2016-1626
DSA-3486-1
DSA-4013-1
MGASA-2016-0127
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2016:0241
RHSA-2016_0241
ZDI-16-171

Produtos afetados

Alt Linux
Google Chrome
Openjpeg
Opera
Pdfium
Red Hat