PT-2016-1192 · Opera+4 · Opera+5

Published

2016-02-09

·

Updated

2024-06-15

·

CVE-2016-1626

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenJPEG versions prior to 48.0.2564.109 Google Chrome versions prior to 48.0.2564.109 PDFium versions prior to 48.0.2564.109 Opera versions prior to 48.0.2564.109
Description The issue is related to the opj pi update decode poc function in pi.c in OpenJPEG, which is used in PDFium in Google Chrome and Opera. This function miscalculates a certain layer index value, allowing remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document. The vulnerability can be exploited by a specially crafted PDF document, leading to a denial of service.
Recommendations For Google Chrome versions prior to 48.0.2564.109, update to version 48.0.2564.109 or later. For Opera versions prior to 48.0.2564.109, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the opj pi update decode poc function in pi.c until a patch is available. Restrict access to PDF documents from untrusted sources to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1098
BDU:2016-00453
CVE-2016-1626
DSA-3486-1
DSA-4013-1
MGASA-2016-0127
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2016:0241
RHSA-2016_0241
ZDI-16-171

Affected Products

Alt Linux
Google Chrome
Openjpeg
Opera
Pdfium
Red Hat