Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-1239

Опубликовано: 18 окт. 2017
Источник: debian
EPSS Низкий

Описание

Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openjpeg2fixed2.1.1-1package

Примечания

  • https://bugs.chromium.org/p/chromium/issues/detail?id=430891

  • https://github.com/uclouvain/openjpeg/issues/477

  • The issue must have been fixed in one of the commits before or with

  • https://github.com/uclouvain/openjpeg/commit/2d24b6000d5611615e3e6d799e20d5fdbe4e2a1e

  • which corresponds to the r2997 commit as mentioned in the merge which

  • fixed the issue on Google/PDFium's side.

EPSS

Процентиль: 74%
0.00828
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.

CVSS3: 6.5
nvd
больше 8 лет назад

Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.

CVSS3: 6.5
github
больше 3 лет назад

Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.

suse-cvrf
больше 7 лет назад

Security update for openjpeg2

suse-cvrf
больше 7 лет назад

Security update for openjpeg2

EPSS

Процентиль: 74%
0.00828
Низкий