PT-2016-1467 · Opera+5 · Opera+6
Published
2016-03-08
·
Updated
2024-06-15
·
CVE-2016-1645
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenJPEG versions prior to 49.0.2623.87
Google Chrome versions prior to 49.0.2623.87
PDFium versions prior to 49.0.2623.87
Opera versions prior to 49.0.2623.87
Description
The issue is caused by multiple integer signedness errors in the
opj j2k update image data function in j2k.c in OpenJPEG, which is used in PDFium in Google Chrome and Opera. This allows remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data.Recommendations
For OpenJPEG versions prior to 49.0.2623.87, update to a version that includes the fix for the
opj j2k update image data function.
For Google Chrome versions prior to 49.0.2623.87, update to version 49.0.2623.87 or later.
For PDFium versions prior to 49.0.2623.87, update to a version that includes the fix for the opj j2k update image data function.
For Opera versions prior to 49.0.2623.87, update to a version that includes the fix for the opj j2k update image data function.
As a temporary workaround, consider disabling the opj j2k update image data function until a patch is available.Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Openjpeg
Opera
Pdfium
Red Hat
Suse