CVE-2015-1273
published 2015-07-23CVE-2015-1273: Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.54%
72.2th percentile
Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid JPEG2000 data in a PDF document.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | <= 43.0.2357.134 | — | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary_eus | — | — |
| redhat | enterprise_linux_workstation_supplementary | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-99jr-cv35-9f59: Heap-based buffer overflow in j2k
ghsa_unreviewed·2022-05-14
CVE-2015-1273 [MEDIUM] CWE-119 GHSA-99jr-cv35-9f59: Heap-based buffer overflow in j2k
Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid JPEG2000 data in a PDF document.
OSV
CVE-2015-1273: Heap-based buffer overflow in j2k
osv·2015-07-23·CVSS 6.8
CVE-2015-1273 [MEDIUM] CVE-2015-1273: Heap-based buffer overflow in j2k
Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid JPEG2000 data in a PDF document.
Red Hat
chromium-browser: Heap-buffer-overflow in pdfium.
vendor_redhat·2015-07-21·CVSS 6.8
CVE-2015-1273 [MEDIUM] CWE-122 chromium-browser: Heap-buffer-overflow in pdfium.
chromium-browser: Heap-buffer-overflow in pdfium.
Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid JPEG2000 data in a PDF document.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1273 chromium-browser: Heap-buffer-overflow in pdfium.
bugzilla·2015-07-22·CVSS 6.8
CVE-2015-1273 [MEDIUM] CVE-2015-1273 chromium-browser: Heap-buffer-overflow in pdfium.
CVE-2015-1273 chromium-browser: Heap-buffer-overflow in pdfium.
An unspecified heap-buffer-overflow flaw was found in the pdfium component of the Chromium browser.
Upstream bug: https://code.google.com/p/chromium/issues/detail?id=459215
External References:
http://googlechromereleases.blogspot.com/2015/07/stable-channel-update_21.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:1499 https://rhn.redhat.com/errata/RHSA-2015-1499.html
Bugzilla
CVE-2014-9721 zeromq: protocol downgrade attack on sockets using the ZMTP v3 protocol
bugzilla·2015-05-14·CVSS 4.3
CVE-2014-9721 [MEDIUM] CVE-2014-9721 zeromq: protocol downgrade attack on sockets using the ZMTP v3 protocol
CVE-2014-9721 zeromq: protocol downgrade attack on sockets using the ZMTP v3 protocol
It was discovered that zeromq, a lightweight messaging kernel, is
susceptible to a protocol downgrade attack on sockets using the ZMTP v3
protocol. This could allow remote attackers to bypass ZMTP v3 security
mechanisms by sending ZMTP v2 or earlier headers.
CVE request: http://openwall.com/lists/oss-security/2015/05/07/8
Upstream bug report: https://github.com/zeromq/libzmq/issues/1273
Upstream fix: https://github.com/zeromq/zeromq4-x/commit/b6e3e0f601e2c1ec1f3aac880ed6a3fe63043e51
Discussion:
If I read the whiteboard correctly fedora-all/zeromq should be not affected by this attack, but in F22 and F23 it is as versions 4.0.5 are used there.
It is fixed in rawhide with:
http://koji.fedoraproject.org
http://googlechromereleases.blogspot.com/2015/07/stable-channel-update_21.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00038.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1499.htmlhttp://www.debian.org/security/2015/dsa-3315http://www.securityfocus.com/bid/75973http://www.securitytracker.com/id/1033031https://code.google.com/p/chromium/issues/detail?id=459215https://pdfium.googlesource.com/pdfium/+/cddfde0cddbc8467e0d5fa04c30405ee257750fchttps://security.gentoo.org/glsa/201603-09http://googlechromereleases.blogspot.com/2015/07/stable-channel-update_21.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00038.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1499.htmlhttp://www.debian.org/security/2015/dsa-3315http://www.securityfocus.com/bid/75973http://www.securitytracker.com/id/1033031https://code.google.com/p/chromium/issues/detail?id=459215https://pdfium.googlesource.com/pdfium/+/cddfde0cddbc8467e0d5fa04c30405ee257750fchttps://security.gentoo.org/glsa/201603-09
2015-07-23
Published