Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5139

Опубликовано: 03 авг. 2016
Источник: redhat
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.

An integer overflow, leading to a heap buffer overflow, was found in openjpeg, also affecting the PDF viewer in Chromium. A specially crafted JPEG2000 image could cause an incorrect calculation when allocating precinct data structures, which could lead to a crash, or potentially, code execution.

Дополнительная информация

Статус:

Important
Дефект:
CWE-190->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1363982openjpeg: Heap overflow in parsing of JPEG2000 precincts

EPSS

Процентиль: 79%
0.01279
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.6
ubuntu
больше 9 лет назад

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.

CVSS3: 7.6
nvd
больше 9 лет назад

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.

CVSS3: 7.6
debian
больше 9 лет назад

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c ...

CVSS3: 7.6
github
больше 3 лет назад

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.

oracle-oval
больше 8 лет назад

ELSA-2017-0559: openjpeg security update (MODERATE)

EPSS

Процентиль: 79%
0.01279
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2