PT-2014-8332 · Google+2 · Google Chrome+3

Published

2014-11-18

·

Updated

2024-06-15

·

CVE-2014-7901

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenJPEG versions prior to the version in Google Chrome 39.0.2171.65
Description The issue is related to an integer overflow in the opj t2 read packet data function, which can be triggered by a long segment in a JPEG image. This can cause a denial of service or possibly have other unspecified impacts. The estimated number of potentially affected devices is not provided.
Recommendations For OpenJPEG versions prior to the version in Google Chrome 39.0.2171.65, update to Google Chrome 39.0.2171.65 or later to resolve the issue. At the moment, there is no information about other versions that contain a fix for this issue.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2430
CVE-2014-7901
OPENSUSE-SU-2014_1626-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Google Chrome
Openjpeg
Suse