PT-2016-1467 · Opera+5 · Opera+6

Published

2016-03-08

·

Updated

2024-06-15

·

CVE-2016-1645

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenJPEG versions prior to 49.0.2623.87 Google Chrome versions prior to 49.0.2623.87 PDFium versions prior to 49.0.2623.87 Opera versions prior to 49.0.2623.87
Description The issue is caused by multiple integer signedness errors in the opj j2k update image data function in j2k.c in OpenJPEG, which is used in PDFium in Google Chrome and Opera. This allows remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data.
Recommendations For OpenJPEG versions prior to 49.0.2623.87, update to a version that includes the fix for the opj j2k update image data function. For Google Chrome versions prior to 49.0.2623.87, update to version 49.0.2623.87 or later. For PDFium versions prior to 49.0.2623.87, update to a version that includes the fix for the opj j2k update image data function. For Opera versions prior to 49.0.2623.87, update to a version that includes the fix for the opj j2k update image data function. As a temporary workaround, consider disabling the opj j2k update image data function until a patch is available.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1283
BDU:2016-00768
CVE-2016-1645
DSA-3513-1
MGASA-2016-0127
OPENSUSE-SU-2016_0817-1
OPENSUSE-SU-2016_0828-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2016:0429
RHSA-2016_0429
ZDI-16-197

Affected Products

Alt Linux
Google Chrome
Openjpeg
Opera
Pdfium
Red Hat
Suse