CVE-2014-7947
published 2015-01-22CVE-2014-7947: OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.73%
75.0th percentile
OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, pi.c, t1.c, t2.c, and tcd.c.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjpeg2 | < openjpeg2 2.1.1-1 (bookworm) | openjpeg2 2.1.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | <= 40.0.2214.85 | — | |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| uclouvain | openjpeg | <= 2.1.0 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g22f-672c-27cg: OpenJPEG before r2944, as used in PDFium in Google Chrome before 40
ghsa_unreviewed·2022-05-17
CVE-2014-7947 [MEDIUM] CWE-119 GHSA-g22f-672c-27cg: OpenJPEG before r2944, as used in PDFium in Google Chrome before 40
OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, pi.c, t1.c, t2.c, and tcd.c.
GHSA
GHSA-g3qh-h448-hf99: Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd
ghsa_unreviewed·2022-05-13·CVSS 5.0
CVE-2016-4797 [MEDIUM] CWE-369 GHSA-g3qh-h448-hf99: Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd
Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of an incorrect fix for CVE-2014-7947.
OSV
CVE-2016-4797: Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd
osv·2017-02-03·CVSS 5.0
CVE-2016-4797 [MEDIUM] CVE-2016-4797: Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd
Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of an incorrect fix for CVE-2014-7947.
OSV
CVE-2014-7947: OpenJPEG before r2944, as used in PDFium in Google Chrome before 40
osv·2015-01-22·CVSS 5.0
CVE-2014-7947 [MEDIUM] CVE-2014-7947: OpenJPEG before r2944, as used in PDFium in Google Chrome before 40
OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, pi.c, t1.c, t2.c, and tcd.c.
Red Hat
openjpeg: Division-by-zero in function opj_tcd_init_tile in tcd.c
vendor_redhat·2016-03-28·CVSS 5.0
CVE-2016-4797 [MEDIUM] CWE-369 openjpeg: Division-by-zero in function opj_tcd_init_tile in tcd.c
openjpeg: Division-by-zero in function opj_tcd_init_tile in tcd.c
Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of an incorrect fix for CVE-2014-7947.
Package: openjpeg (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-4797: openjpeg2 - Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJ...
vendor_debian·2016·CVSS 5.0
CVE-2016-4797 [MEDIUM] CVE-2016-4797: openjpeg2 - Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJ...
Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of an incorrect fix for CVE-2014-7947.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
bullseye: resolved (fixed in 2.1.1-1)
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixed in 2.1.1-1)
trixie: resolved (fixed in 2.1.1-1)
Red Hat
chromium-browser: out-of-bounds read in PDFium
vendor_redhat·2015-01-21·CVSS 5.0
CVE-2014-7947 [MEDIUM] CWE-125 chromium-browser: out-of-bounds read in PDFium
chromium-browser: out-of-bounds read in PDFium
OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, pi.c, t1.c, t2.c, and tcd.c.
Debian
CVE-2014-7947: openjpeg2 - OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, a...
vendor_debian·2014·CVSS 5.0
CVE-2014-7947 [MEDIUM] CVE-2014-7947: openjpeg2 - OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, a...
OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, pi.c, t1.c, t2.c, and tcd.c.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
bullseye: resolved (fixed in 2.1.1-1)
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixed in 2.1.1-1)
trixie: resolved (fixed in 2.1.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4797 openjpeg: Division-by-zero in function opj_tcd_init_tile in tcd.c
bugzilla·2016-05-12·CVSS 5.0
CVE-2016-4797 [MEDIUM] CVE-2016-4797 openjpeg: Division-by-zero in function opj_tcd_init_tile in tcd.c
CVE-2016-4797 openjpeg: Division-by-zero in function opj_tcd_init_tile in tcd.c
Divide by zero vulnerability was found in function opj_tcd_init_tile in tcd.c
Upstream patch:
https://github.com/uclouvain/openjpeg/commit/8f9cc62b3f9a1da9712329ddcedb9750d585505c
CVE request:
http://seclists.org/oss-sec/2016/q2/327
Discussion:
Created mingw-openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1335485]
---
Created openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1335484]
Affects: epel-all [bug 1335486]
---
CVE assignment:
http://seclists.org/oss-sec/2016/q2/342
Note that the problematic "(OPJ_UINT32)-1) / l_data_size" was apparently introduced in a patch addressing out-of-bounds read (or heap-based buffer over-read) vulnerabilities. See the pdfium.goog
Bugzilla
CVE-2014-7947 chromium-browser: out-of-bounds read in PDFium
bugzilla·2015-01-23·CVSS 5.0
CVE-2014-7947 [MEDIUM] CVE-2014-7947 chromium-browser: out-of-bounds read in PDFium
CVE-2014-7947 chromium-browser: out-of-bounds read in PDFium
An unspecified out-of-bounds read flaw was found in the PDFium component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
http://googlechromereleases.blogspot.com/2015/01/stable-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0093.htmlhttp://secunia.com/advisories/62383http://secunia.com/advisories/62665http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.securityfocus.com/bid/72288http://www.securitytracker.com/id/1031623https://code.google.com/p/chromium/issues/detail?id=430566https://pdfium.googlesource.com/pdfium/+/66d6538c0a97cff550cafdfeaebe8a3f0efbad89http://googlechromereleases.blogspot.com/2015/01/stable-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0093.htmlhttp://secunia.com/advisories/62383http://secunia.com/advisories/62665http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.securityfocus.com/bid/72288http://www.securitytracker.com/id/1031623https://code.google.com/p/chromium/issues/detail?id=430566https://pdfium.googlesource.com/pdfium/+/66d6538c0a97cff550cafdfeaebe8a3f0efbad89
2015-01-22
Published