PT-2016-2157 · Opera+5 · Opera+6

Aleksandar Nikolic

·

Publicado

2016-05-25

·

Atualizado

2024-06-15

·

CVE-2016-1681

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 51.0.2704.63 OpenJPEG (affected versions not specified) PDFium (affected versions not specified) Opera (affected versions not specified)
Description The issue is caused by a heap-based buffer overflow in the opj j2k read SPCod SPCoc function in j2k.c of the OpenJPEG module, as used in PDFium. This can be exploited by remote attackers using a specially crafted PDF document, potentially leading to a denial of service or other unspecified impacts.
Recommendations For Google Chrome versions prior to 51.0.2704.63, update to version 51.0.2704.63 or later. For OpenJPEG, PDFium, and Opera, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the opj j2k read SPCod SPCoc function in the j2k.c file until a patch is available. Avoid using the OpenJPEG module in PDFium for processing PDF documents until the issue is resolved.

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2194
BDU:2016-01510
CVE-2016-1681
DSA-3590-1
MGASA-2016-0214
OPENSUSE-SU-2016_1430-1
OPENSUSE-SU-2016_1496-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2016:1190
RHSA-2016_1190

Produtos afetados

Alt Linux
Google Chrome
Openjpeg
Opera
Pdfium
Red Hat
Suse