Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5152

Опубликовано: 31 авг. 2016
Источник: redhat
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5openjpegNot affected
Red Hat Enterprise Linux 6openjpegNot affected
Red Hat Enterprise Linux 7openjpegNot affected
Red Hat Enterprise Linux 6 Supplementarychromium-browserFixedRHSA-2016:185412.09.2016

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1372213chromium-browser: heap overflow in pdfium

EPSS

Процентиль: 77%
0.01001
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 9 лет назад

Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.

CVSS3: 8.8
nvd
больше 9 лет назад

Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.

CVSS3: 8.8
debian
больше 9 лет назад

Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd. ...

CVSS3: 8.8
github
больше 3 лет назад

Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.

EPSS

Процентиль: 77%
0.01001
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2