PT-2016-2157 · Opera+5 · Opera+6
Aleksandar Nikolic
·
Published
2016-05-25
·
Updated
2024-06-15
·
CVE-2016-1681
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 51.0.2704.63
OpenJPEG (affected versions not specified)
PDFium (affected versions not specified)
Opera (affected versions not specified)
Description
The issue is caused by a heap-based buffer overflow in the
opj j2k read SPCod SPCoc function in j2k.c of the OpenJPEG module, as used in PDFium. This can be exploited by remote attackers using a specially crafted PDF document, potentially leading to a denial of service or other unspecified impacts.Recommendations
For Google Chrome versions prior to 51.0.2704.63, update to version 51.0.2704.63 or later.
For OpenJPEG, PDFium, and Opera, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the
opj j2k read SPCod SPCoc function in the j2k.c file until a patch is available. Avoid using the OpenJPEG module in PDFium for processing PDF documents until the issue is resolved.DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Openjpeg
Opera
Pdfium
Red Hat
Suse