CVE-2015-6581 — Out-of-bounds Write in Google Chrome

10 documents7 sources
Severity
7.5HIGHNVD
EPSS
2.3%
top 15.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 3
Latest updateMay 17

Description

Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering a memory-allocation failure.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

â–¶NVDgoogle/chrome44.0.2403
â–¶Debianthe_openjpeg_project/openjpeg2< 2.1.1-1+3

🔴Vulnerability Details

3
GHSA
GHSA-gphr-q83r-f4gv: Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k↗2022-05-17
â–¶
OSV
CVE-2015-6581: Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k↗2015-09-03
â–¶
CVEList
CVE-2015-6581: Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k↗2015-09-03
â–¶

📋Vendor Advisories

2
Red Hat
openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd↗2015-05-19
â–¶
Debian
CVE-2015-6581: openjpeg2 - Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd functio...↗2015
â–¶

💬Community

4
Bugzilla
CVE-2015-6581 openjpeg2: openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd [fedora-all]↗2015-10-01
â–¶
Bugzilla
CVE-2015-6581 openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd [fedora-all]↗2015-10-01
â–¶
Bugzilla
CVE-2015-6581 openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd↗2015-10-01
â–¶
Bugzilla
CVE-2015-6581 mingw-openjpeg: openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd [fedora-all]↗2015-10-01
â–¶
CVE-2015-6581 — Out-of-bounds Write in Google Chrome | cvebase