PT-2016-2157 · Opera+5 · Opera+6

Aleksandar Nikolic

·

Published

2016-05-25

·

Updated

2024-06-15

·

CVE-2016-1681

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 51.0.2704.63 OpenJPEG (affected versions not specified) PDFium (affected versions not specified) Opera (affected versions not specified)
Description The issue is caused by a heap-based buffer overflow in the opj j2k read SPCod SPCoc function in j2k.c of the OpenJPEG module, as used in PDFium. This can be exploited by remote attackers using a specially crafted PDF document, potentially leading to a denial of service or other unspecified impacts.
Recommendations For Google Chrome versions prior to 51.0.2704.63, update to version 51.0.2704.63 or later. For OpenJPEG, PDFium, and Opera, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the opj j2k read SPCod SPCoc function in the j2k.c file until a patch is available. Avoid using the OpenJPEG module in PDFium for processing PDF documents until the issue is resolved.

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2194
BDU:2016-01510
CVE-2016-1681
DSA-3590-1
MGASA-2016-0214
OPENSUSE-SU-2016_1430-1
OPENSUSE-SU-2016_1496-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2016:1190
RHSA-2016_1190

Affected Products

Alt Linux
Google Chrome
Openjpeg
Opera
Pdfium
Red Hat
Suse