CVE-2015-6581
published 2015-09-03CVE-2015-6581: Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.68%
84.1th percentile
Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering a memory-allocation failure.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjpeg2 | < openjpeg2 2.1.1-1 (bookworm) | openjpeg2 2.1.1-1 (bookworm) |
| chrome | <= 44.0.2403 | — | |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gphr-q83r-f4gv: Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k
ghsa_unreviewed·2022-05-17
CVE-2015-6581 [HIGH] GHSA-gphr-q83r-f4gv: Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k
Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering a memory-allocation failure.
OSV
CVE-2015-6581: Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k
osv·2015-09-03·CVSS 7.5
CVE-2015-6581 [HIGH] CVE-2015-6581: Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k
Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering a memory-allocation failure.
Red Hat
openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd
vendor_redhat·2015-05-19·CVSS 7.5
CVE-2015-6581 [HIGH] openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd
openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd
Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering a memory-allocation failure.
Statement: Not vulnerable. This issue did not affect the versions of openjpeg as shipped
with Red Hat Enterprise Linux 6 and 7.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2015-6581: openjpeg2 - Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd functio...
vendor_debian·2015·CVSS 7.5
CVE-2015-6581 [HIGH] CVE-2015-6581: openjpeg2 - Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd functio...
Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering a memory-allocation failure.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
bullseye: resolved (fixed in 2.1.1-1)
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixed in 2.1.1-1)
trixie: resolved (fixed in 2.1.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-6581 openjpeg2: openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd [fedora-all]
bugzilla·2015-10-01·CVSS 7.5
CVE-2015-6581 [HIGH] CVE-2015-6581 openjpeg2: openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd [fedora-all]
CVE-2015-6581 openjpeg2: openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2015-6581 openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd [fedora-all]
bugzilla·2015-10-01·CVSS 7.5
CVE-2015-6581 [HIGH] CVE-2015-6581 openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd [fedora-all]
CVE-2015-6581 openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2015-6581 openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd
bugzilla·2015-10-01·CVSS 7.5
CVE-2015-6581 [HIGH] CVE-2015-6581 openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd
CVE-2015-6581 openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd
Double-free vulnerability was found in opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allowing remote attacker to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering a memory-allocation failure.
The opj_j2k_copy_default_tcp_and_create_tcp() function memcpy's a top-level
struct and then replaces pointers to memory owned by the original struct
with new blocks of memory. Unfortunately, an early return can leave the
copy with pointers to memory it doesn't own, which causes problems when
cleaning up the partially-initialized struct.
Upstream bug:
https://code.google.com
Bugzilla
CVE-2015-6581 mingw-openjpeg: openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd [fedora-all]
bugzilla·2015-10-01·CVSS 7.5
CVE-2015-6581 [HIGH] CVE-2015-6581 mingw-openjpeg: openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd [fedora-all]
CVE-2015-6581 mingw-openjpeg: openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168736.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169258.htmlhttp://www.debian.org/security/2016/dsa-3665http://www.securitytracker.com/id/1033472https://code.google.com/p/chromium/issues/detail?id=486538https://code.google.com/p/chromium/issues/detail?id=526825https://code.google.com/p/openjpeg/issues/detail?id=492http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168736.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169258.htmlhttp://www.debian.org/security/2016/dsa-3665http://www.securitytracker.com/id/1033472https://code.google.com/p/chromium/issues/detail?id=486538https://code.google.com/p/chromium/issues/detail?id=526825https://code.google.com/p/openjpeg/issues/detail?id=492
2015-09-03
Published